From: Leon Hwang <leon.hwang@linux.dev>
To: bpf@vger.kernel.org
Cc: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org,
toke@redhat.com, martin.lau@kernel.org, yonghong.song@linux.dev,
puranjay@kernel.org, xukuohai@huaweicloud.com, eddyz87@gmail.com,
iii@linux.ibm.com, leon.hwang@linux.dev,
kernel-patches-bot@fb.com
Subject: [PATCH bpf-next v2 0/4] bpf: Fix tailcall infinite loop caused by freplace
Date: Sun, 1 Sep 2024 21:38:52 +0800 [thread overview]
Message-ID: <20240901133856.64367-1-leon.hwang@linux.dev> (raw)
Previously, I fixed a tailcall infinite loop issue caused by trampoline[0].
At this time, I fix a tailcall infinite loop issue caused by freplace.
Since commit 1c123c567fb1 ("bpf: Resolve fext program type when checking map compatibility"),
freplace prog is able to tail call its target prog.
What happens when freplace prog attaches to its target prog's subprog and
tail calls its target prog?
The kernel will panic because TASK stack guard page was hit.
The panic is fixed on both x64 and arm64[1]. Please check the corresponding
patch to see the details.
v1 -> v2:
* Address comment from Eduard:
* Explain why nop5 and xor/nop3 are swapped at prologue.
* Address comment from Alexei:
* Disallow attaching tail_call_reachable freplace prog to
not-tail_call_reachable target in verifier.
* Update "bpf, arm64: Fix tailcall infinite loop caused by freplace" with
latest arm64 JIT code.
Links:
[0] https://lore.kernel.org/bpf/20230912150442.2009-1-hffilwlqm@gmail.com/
[1] https://github.com/kernel-patches/bpf/pull/7638
Leon Hwang (4):
bpf, x64: Fix tailcall infinite loop caused by freplace
bpf, arm64: Fix tailcall infinite loop caused by freplace
selftests/bpf: Add testcases for another tailcall infinite loop fixing
selftests/bpf: Fix verifier tailcall jit selftest
arch/arm64/net/bpf_jit_comp.c | 44 +++-
arch/x86/net/bpf_jit_comp.c | 26 ++-
kernel/bpf/verifier.c | 6 +
.../selftests/bpf/prog_tests/tailcalls.c | 216 +++++++++++++++++-
.../tailcall_bpf2bpf_hierarchy_freplace.c | 30 +++
.../testing/selftests/bpf/progs/tc_bpf2bpf.c | 37 ++-
.../bpf/progs/verifier_tailcall_jit.c | 4 +-
7 files changed, 344 insertions(+), 19 deletions(-)
create mode 100644 tools/testing/selftests/bpf/progs/tailcall_bpf2bpf_hierarchy_freplace.c
--
2.44.0
next reply other threads:[~2024-09-01 13:40 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-01 13:38 Leon Hwang [this message]
2024-09-01 13:38 ` [PATCH bpf-next v2 1/4] bpf, x64: Fix tailcall infinite loop caused by freplace Leon Hwang
2024-09-13 19:28 ` Alexei Starovoitov
2024-09-15 13:00 ` Leon Hwang
2024-09-01 13:38 ` [PATCH bpf-next v2 2/4] bpf, arm64: " Leon Hwang
2024-09-08 13:01 ` Leon Hwang
2024-09-09 9:02 ` Xu Kuohai
2024-09-09 10:38 ` Leon Hwang
2024-09-09 12:08 ` Xu Kuohai
2024-09-09 14:42 ` Leon Hwang
2024-09-13 17:47 ` Alexei Starovoitov
2024-09-14 9:14 ` Xu Kuohai
2024-09-01 13:38 ` [PATCH bpf-next v2 3/4] selftests/bpf: Add testcases for another tailcall infinite loop fixing Leon Hwang
2024-09-01 13:38 ` [PATCH bpf-next v2 4/4] selftests/bpf: Fix verifier tailcall jit selftest Leon Hwang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240901133856.64367-1-leon.hwang@linux.dev \
--to=leon.hwang@linux.dev \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=iii@linux.ibm.com \
--cc=kernel-patches-bot@fb.com \
--cc=martin.lau@kernel.org \
--cc=puranjay@kernel.org \
--cc=toke@redhat.com \
--cc=xukuohai@huaweicloud.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.