* [PATCH bpf-next 0/2] bpf, riscv: Add support for signed arena loads
@ 2026-08-17 7:24 ` Chen Pei
0 siblings, 0 replies; 8+ messages in thread
From: Chen Pei @ 2026-08-17 7:24 UTC (permalink / raw)
To: ast, daniel, andrii, memxor, bjorn, puranjay
Cc: eddyz87, martin.lau, song, yonghong.song, jolsa, emil, pulehui,
pjw, palmer, shuah, guoren, bpf, linux-riscv, linux-kselftest,
linux-kernel
Hi,
Signed loads from arena memory are currently unsupported on riscv64:
bpf_jit_supports_insn() rejects BPF_MEMSX loads when in_arena is set,
so the verifier fails such programs with "sign extending loads from
arena are not supported yet". The x86 and arm64 JITs gained support
for them in v6.18 (a91ae3c89311, eab2a71f3a6a). Since compilers are
free to generate signed loads into arena memory (e.g. GCC-14 was
reported to do so), otherwise valid BPF programs fail to load on
riscv64.
This series adds BPF_PROBE_MEM32SX support to the RV64 JIT and
enables the corresponding selftests on riscv64:
1 implements signed arena loads in the RV64 JIT. The verifier
already converts MEMSX loads from PTR_TO_ARENA to
BPF_PROBE_MEM32SX once bpf_jit_supports_insn() allows them, so
the JIT reuses the existing arena handling: the arena base
(RV_REG_ARENA) is added to the source register and the load is
emitted with sign extension (lb/lh/lw). BPF_PROBE_MEM32SX is also
added to the add_exception_handler() mode gate so faulting loads
register an exception table entry that clears the destination
register and resumes execution.
2 enables the arena LDSX tests on riscv64: JIT disassembly
assertions are added to arena_ldsx_disasm, and
arena_ldsx_exception/s8/s16/s32 are now run on riscv64.
The series was verified on riscv64 with QEMU (-M virt -cpu max): all
five arena_ldsx tests pass, including the exception path (load from
unallocated arena memory returns 0) and the sign-extension values
(s8/s16/s32 tests return -1 as expected).
Note: the __jited assertions in patch 2 were derived from the JIT
register allocation (R0->a5, R1->a0, R8->s3, R9->s4, arena base in
s7) and the emit_ldx() code paths; happy to adjust them if a
disassembler output detail differs.
Thanks,
Pei
Chen Pei (2):
bpf, riscv: Add support for signed arena loads
selftests/bpf: Enable arena LDSX tests for riscv64
arch/riscv/net/bpf_jit_comp64.c | 15 +++++++++------
.../testing/selftests/bpf/progs/verifier_ldsx.c | 17 +++++++++++++++++
2 files changed, 26 insertions(+), 6 deletions(-)
--
2.50.1
_______________________________________________
linux-riscv mailing list
linux-riscv@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-riscv
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH bpf-next 1/2] bpf, riscv: Add support for signed arena loads
2026-08-17 7:24 ` Chen Pei
@ 2026-08-17 7:24 ` Chen Pei
-1 siblings, 0 replies; 8+ messages in thread
From: Chen Pei @ 2026-08-17 7:24 UTC (permalink / raw)
To: ast, daniel, andrii, memxor, bjorn, puranjay
Cc: eddyz87, martin.lau, song, yonghong.song, jolsa, emil, pulehui,
pjw, palmer, shuah, guoren, bpf, linux-riscv, linux-kselftest,
linux-kernel
Signed loads from arena memory are currently rejected on riscv64, as
bpf_jit_supports_insn() refuses BPF_MEMSX loads when in_arena is set,
while x86 and arm64 gained support for them in v6.18. Compilers such
as GCC-14 are free to generate signed loads into arena memory, which
breaks loading of otherwise valid BPF programs on riscv64.
Implement BPF_PROBE_MEM32SX support in the RV64 JIT by reusing the
existing arena handling: the arena base (RV_REG_ARENA) is added to
the source register and the load is emitted with sign extension
(lb/lh/lw). Add BPF_PROBE_MEM32SX to the add_exception_handler()
mode gate so that faulting loads get an exception table entry which
clears the destination register and resumes execution.
Verified by running the arena LDSX selftests (arena_ldsx_disasm,
arena_ldsx_exception, arena_ldsx_s8/s16/s32) on riscv64 QEMU, all
passing.
Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
---
arch/riscv/net/bpf_jit_comp64.c | 15 +++++++++------
1 file changed, 9 insertions(+), 6 deletions(-)
diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
index f9d5347ba966..5786f7dfc8a7 100644
--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -777,6 +777,7 @@ static int add_exception_handler(const struct bpf_insn *insn, int dst_reg,
if (BPF_MODE(insn->code) != BPF_PROBE_MEM &&
BPF_MODE(insn->code) != BPF_PROBE_MEMSX &&
BPF_MODE(insn->code) != BPF_PROBE_MEM32 &&
+ BPF_MODE(insn->code) != BPF_PROBE_MEM32SX &&
BPF_MODE(insn->code) != BPF_PROBE_ATOMIC)
return 0;
@@ -1902,13 +1903,19 @@ int bpf_jit_emit_insn(const struct bpf_insn *insn, struct rv_jit_context *ctx,
case BPF_LDX | BPF_PROBE_MEM32 | BPF_H:
case BPF_LDX | BPF_PROBE_MEM32 | BPF_W:
case BPF_LDX | BPF_PROBE_MEM32 | BPF_DW:
+ /* LDX | PROBE_MEM32SX: dst = *(signed size *)(src + RV_REG_ARENA + off) */
+ case BPF_LDX | BPF_PROBE_MEM32SX | BPF_B:
+ case BPF_LDX | BPF_PROBE_MEM32SX | BPF_H:
+ case BPF_LDX | BPF_PROBE_MEM32SX | BPF_W:
{
bool sign_ext;
sign_ext = BPF_MODE(insn->code) == BPF_MEMSX ||
- BPF_MODE(insn->code) == BPF_PROBE_MEMSX;
+ BPF_MODE(insn->code) == BPF_PROBE_MEMSX ||
+ BPF_MODE(insn->code) == BPF_PROBE_MEM32SX;
- if (BPF_MODE(insn->code) == BPF_PROBE_MEM32) {
+ if (BPF_MODE(insn->code) == BPF_PROBE_MEM32 ||
+ BPF_MODE(insn->code) == BPF_PROBE_MEM32SX) {
emit_add(RV_REG_T2, rs, RV_REG_ARENA, ctx);
rs = RV_REG_T2;
}
@@ -2126,10 +2133,6 @@ bool bpf_jit_supports_insn(struct bpf_insn *insn, bool in_arena)
if (insn->imm == BPF_CMPXCHG)
return rv_ext_enabled(ZACAS);
break;
- case BPF_LDX | BPF_MEMSX | BPF_B:
- case BPF_LDX | BPF_MEMSX | BPF_H:
- case BPF_LDX | BPF_MEMSX | BPF_W:
- return false;
}
}
--
2.50.1
^ permalink raw reply related [flat|nested] 8+ messages in thread* [PATCH bpf-next 1/2] bpf, riscv: Add support for signed arena loads
@ 2026-08-17 7:24 ` Chen Pei
0 siblings, 0 replies; 8+ messages in thread
From: Chen Pei @ 2026-08-17 7:24 UTC (permalink / raw)
To: ast, daniel, andrii, memxor, bjorn, puranjay
Cc: eddyz87, martin.lau, song, yonghong.song, jolsa, emil, pulehui,
pjw, palmer, shuah, guoren, bpf, linux-riscv, linux-kselftest,
linux-kernel
Signed loads from arena memory are currently rejected on riscv64, as
bpf_jit_supports_insn() refuses BPF_MEMSX loads when in_arena is set,
while x86 and arm64 gained support for them in v6.18. Compilers such
as GCC-14 are free to generate signed loads into arena memory, which
breaks loading of otherwise valid BPF programs on riscv64.
Implement BPF_PROBE_MEM32SX support in the RV64 JIT by reusing the
existing arena handling: the arena base (RV_REG_ARENA) is added to
the source register and the load is emitted with sign extension
(lb/lh/lw). Add BPF_PROBE_MEM32SX to the add_exception_handler()
mode gate so that faulting loads get an exception table entry which
clears the destination register and resumes execution.
Verified by running the arena LDSX selftests (arena_ldsx_disasm,
arena_ldsx_exception, arena_ldsx_s8/s16/s32) on riscv64 QEMU, all
passing.
Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
---
arch/riscv/net/bpf_jit_comp64.c | 15 +++++++++------
1 file changed, 9 insertions(+), 6 deletions(-)
diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
index f9d5347ba966..5786f7dfc8a7 100644
--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -777,6 +777,7 @@ static int add_exception_handler(const struct bpf_insn *insn, int dst_reg,
if (BPF_MODE(insn->code) != BPF_PROBE_MEM &&
BPF_MODE(insn->code) != BPF_PROBE_MEMSX &&
BPF_MODE(insn->code) != BPF_PROBE_MEM32 &&
+ BPF_MODE(insn->code) != BPF_PROBE_MEM32SX &&
BPF_MODE(insn->code) != BPF_PROBE_ATOMIC)
return 0;
@@ -1902,13 +1903,19 @@ int bpf_jit_emit_insn(const struct bpf_insn *insn, struct rv_jit_context *ctx,
case BPF_LDX | BPF_PROBE_MEM32 | BPF_H:
case BPF_LDX | BPF_PROBE_MEM32 | BPF_W:
case BPF_LDX | BPF_PROBE_MEM32 | BPF_DW:
+ /* LDX | PROBE_MEM32SX: dst = *(signed size *)(src + RV_REG_ARENA + off) */
+ case BPF_LDX | BPF_PROBE_MEM32SX | BPF_B:
+ case BPF_LDX | BPF_PROBE_MEM32SX | BPF_H:
+ case BPF_LDX | BPF_PROBE_MEM32SX | BPF_W:
{
bool sign_ext;
sign_ext = BPF_MODE(insn->code) == BPF_MEMSX ||
- BPF_MODE(insn->code) == BPF_PROBE_MEMSX;
+ BPF_MODE(insn->code) == BPF_PROBE_MEMSX ||
+ BPF_MODE(insn->code) == BPF_PROBE_MEM32SX;
- if (BPF_MODE(insn->code) == BPF_PROBE_MEM32) {
+ if (BPF_MODE(insn->code) == BPF_PROBE_MEM32 ||
+ BPF_MODE(insn->code) == BPF_PROBE_MEM32SX) {
emit_add(RV_REG_T2, rs, RV_REG_ARENA, ctx);
rs = RV_REG_T2;
}
@@ -2126,10 +2133,6 @@ bool bpf_jit_supports_insn(struct bpf_insn *insn, bool in_arena)
if (insn->imm == BPF_CMPXCHG)
return rv_ext_enabled(ZACAS);
break;
- case BPF_LDX | BPF_MEMSX | BPF_B:
- case BPF_LDX | BPF_MEMSX | BPF_H:
- case BPF_LDX | BPF_MEMSX | BPF_W:
- return false;
}
}
--
2.50.1
_______________________________________________
linux-riscv mailing list
linux-riscv@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-riscv
^ permalink raw reply related [flat|nested] 8+ messages in thread* Re: [PATCH bpf-next 1/2] bpf, riscv: Add support for signed arena loads
2026-08-17 7:24 ` Chen Pei
@ 2026-08-17 8:16 ` bot+bpf-ci
-1 siblings, 0 replies; 8+ messages in thread
From: bot+bpf-ci @ 2026-08-17 8:16 UTC (permalink / raw)
To: cp0613, ast, daniel, andrii, memxor, bjorn, puranjay
Cc: eddyz87, martin.lau, song, yonghong.song, jolsa, emil, pulehui,
pjw, palmer, shuah, guoren, bpf, linux-riscv, linux-kselftest,
linux-kernel, ast, andrii, daniel, martin.lau, eddyz87,
yonghong.song, clm, ihor.solodrai
[-- Attachment #1: Type: text/plain, Size: 1486 bytes --]
> bpf, riscv: Add support for signed arena loads
>
> Signed loads from arena memory are currently rejected on riscv64, as
> bpf_jit_supports_insn() refuses BPF_MEMSX loads when in_arena is set,
> while x86 and arm64 gained support for them in v6.18. Compilers such
> as GCC-14 are free to generate signed loads into arena memory, which
> breaks loading of otherwise valid BPF programs on riscv64.
>
> Implement BPF_PROBE_MEM32SX support in the RV64 JIT by reusing the
> existing arena handling: the arena base (RV_REG_ARENA) is added to
> the source register and the load is emitted with sign extension
> (lb/lh/lw). Add BPF_PROBE_MEM32SX to the add_exception_handler()
> mode gate so that faulting loads get an exception table entry which
> clears the destination register and resumes execution.
>
> Verified by running the arena LDSX selftests (arena_ldsx_disasm,
> arena_ldsx_exception, arena_ldsx_s8/s16/s32) on riscv64 QEMU, all
> passing.
>
> Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
This looks like a bug fix for incomplete arena support added by commit
fb7cefabae81. Should this include:
Fixes: fb7cefabae81 ("riscv, bpf: Add support arena atomics for RV64")
---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
CI run summary: https://github.com/kernel-patches/bpf/actions/runs/32007452800
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: [PATCH bpf-next 1/2] bpf, riscv: Add support for signed arena loads
@ 2026-08-17 8:16 ` bot+bpf-ci
0 siblings, 0 replies; 8+ messages in thread
From: bot+bpf-ci @ 2026-08-17 8:16 UTC (permalink / raw)
To: cp0613, ast, daniel, andrii, memxor, bjorn, puranjay
Cc: eddyz87, martin.lau, song, yonghong.song, jolsa, emil, pulehui,
pjw, palmer, shuah, guoren, bpf, linux-riscv, linux-kselftest,
linux-kernel, ast, andrii, daniel, martin.lau, eddyz87,
yonghong.song, clm, ihor.solodrai
[-- Attachment #1: Type: text/plain, Size: 1486 bytes --]
> bpf, riscv: Add support for signed arena loads
>
> Signed loads from arena memory are currently rejected on riscv64, as
> bpf_jit_supports_insn() refuses BPF_MEMSX loads when in_arena is set,
> while x86 and arm64 gained support for them in v6.18. Compilers such
> as GCC-14 are free to generate signed loads into arena memory, which
> breaks loading of otherwise valid BPF programs on riscv64.
>
> Implement BPF_PROBE_MEM32SX support in the RV64 JIT by reusing the
> existing arena handling: the arena base (RV_REG_ARENA) is added to
> the source register and the load is emitted with sign extension
> (lb/lh/lw). Add BPF_PROBE_MEM32SX to the add_exception_handler()
> mode gate so that faulting loads get an exception table entry which
> clears the destination register and resumes execution.
>
> Verified by running the arena LDSX selftests (arena_ldsx_disasm,
> arena_ldsx_exception, arena_ldsx_s8/s16/s32) on riscv64 QEMU, all
> passing.
>
> Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
This looks like a bug fix for incomplete arena support added by commit
fb7cefabae81. Should this include:
Fixes: fb7cefabae81 ("riscv, bpf: Add support arena atomics for RV64")
---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
CI run summary: https://github.com/kernel-patches/bpf/actions/runs/32007452800
[-- Attachment #2: Type: text/plain, Size: 161 bytes --]
_______________________________________________
linux-riscv mailing list
linux-riscv@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-riscv
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH bpf-next 2/2] selftests/bpf: Enable arena LDSX tests for riscv64
2026-08-17 7:24 ` Chen Pei
@ 2026-08-17 7:24 ` Chen Pei
-1 siblings, 0 replies; 8+ messages in thread
From: Chen Pei @ 2026-08-17 7:24 UTC (permalink / raw)
To: ast, daniel, andrii, memxor, bjorn, puranjay
Cc: eddyz87, martin.lau, song, yonghong.song, jolsa, emil, pulehui,
pjw, palmer, shuah, guoren, bpf, linux-riscv, linux-kselftest,
linux-kernel
Now that the riscv64 JIT supports signed arena loads
(BPF_PROBE_MEM32SX), enable the arena LDSX tests on riscv64:
add JIT disassembly assertions for arena_ldsx_disasm (arena base in
s7, add into t2, sign-extending lw/lh/lb loads) and run
arena_ldsx_exception and arena_ldsx_s8/s16/s32 on riscv64.
Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
---
.../testing/selftests/bpf/progs/verifier_ldsx.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/tools/testing/selftests/bpf/progs/verifier_ldsx.c b/tools/testing/selftests/bpf/progs/verifier_ldsx.c
index 41340877dc9d..ed0a0f159bc1 100644
--- a/tools/testing/selftests/bpf/progs/verifier_ldsx.c
+++ b/tools/testing/selftests/bpf/progs/verifier_ldsx.c
@@ -286,6 +286,19 @@ __jited("add x11, x0, x28")
__jited("ldrsh x22, [x11, #0x18]")
__jited("add x11, x0, x28")
__jited("ldrsb x22, [x11, #0x20]")
+__arch_riscv64
+__jited("add t2, a5, s7")
+__jited("lw s3, 0x10(t2)")
+__jited("add t2, a5, s7")
+__jited("lh s3, 0x18(t2)")
+__jited("add t2, a5, s7")
+__jited("lb s3, 0x20(t2)")
+__jited("add t2, a0, s7")
+__jited("lw s4, 0x10(t2)")
+__jited("add t2, a0, s7")
+__jited("lh s4, 0x18(t2)")
+__jited("add t2, a0, s7")
+__jited("lb s4, 0x20(t2)")
__naked void arena_ldsx_disasm(void *ctx)
{
asm volatile (
@@ -317,6 +330,7 @@ __description("Arena LDSX Exception")
__success __retval(0)
__arch_x86_64
__arch_arm64
+__arch_riscv64
__naked void arena_ldsx_exception(void *ctx)
{
asm volatile (
@@ -338,6 +352,7 @@ __description("Arena LDSX, S8")
__success __retval(-1)
__arch_x86_64
__arch_arm64
+__arch_riscv64
__naked void arena_ldsx_s8(void *ctx)
{
asm volatile (
@@ -369,6 +384,7 @@ __description("Arena LDSX, S16")
__success __retval(-1)
__arch_x86_64
__arch_arm64
+__arch_riscv64
__naked void arena_ldsx_s16(void *ctx)
{
asm volatile (
@@ -400,6 +416,7 @@ __description("Arena LDSX, S32")
__success __retval(-1)
__arch_x86_64
__arch_arm64
+__arch_riscv64
__naked void arena_ldsx_s32(void *ctx)
{
asm volatile (
--
2.50.1
^ permalink raw reply related [flat|nested] 8+ messages in thread* [PATCH bpf-next 2/2] selftests/bpf: Enable arena LDSX tests for riscv64
@ 2026-08-17 7:24 ` Chen Pei
0 siblings, 0 replies; 8+ messages in thread
From: Chen Pei @ 2026-08-17 7:24 UTC (permalink / raw)
To: ast, daniel, andrii, memxor, bjorn, puranjay
Cc: eddyz87, martin.lau, song, yonghong.song, jolsa, emil, pulehui,
pjw, palmer, shuah, guoren, bpf, linux-riscv, linux-kselftest,
linux-kernel
Now that the riscv64 JIT supports signed arena loads
(BPF_PROBE_MEM32SX), enable the arena LDSX tests on riscv64:
add JIT disassembly assertions for arena_ldsx_disasm (arena base in
s7, add into t2, sign-extending lw/lh/lb loads) and run
arena_ldsx_exception and arena_ldsx_s8/s16/s32 on riscv64.
Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
---
.../testing/selftests/bpf/progs/verifier_ldsx.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/tools/testing/selftests/bpf/progs/verifier_ldsx.c b/tools/testing/selftests/bpf/progs/verifier_ldsx.c
index 41340877dc9d..ed0a0f159bc1 100644
--- a/tools/testing/selftests/bpf/progs/verifier_ldsx.c
+++ b/tools/testing/selftests/bpf/progs/verifier_ldsx.c
@@ -286,6 +286,19 @@ __jited("add x11, x0, x28")
__jited("ldrsh x22, [x11, #0x18]")
__jited("add x11, x0, x28")
__jited("ldrsb x22, [x11, #0x20]")
+__arch_riscv64
+__jited("add t2, a5, s7")
+__jited("lw s3, 0x10(t2)")
+__jited("add t2, a5, s7")
+__jited("lh s3, 0x18(t2)")
+__jited("add t2, a5, s7")
+__jited("lb s3, 0x20(t2)")
+__jited("add t2, a0, s7")
+__jited("lw s4, 0x10(t2)")
+__jited("add t2, a0, s7")
+__jited("lh s4, 0x18(t2)")
+__jited("add t2, a0, s7")
+__jited("lb s4, 0x20(t2)")
__naked void arena_ldsx_disasm(void *ctx)
{
asm volatile (
@@ -317,6 +330,7 @@ __description("Arena LDSX Exception")
__success __retval(0)
__arch_x86_64
__arch_arm64
+__arch_riscv64
__naked void arena_ldsx_exception(void *ctx)
{
asm volatile (
@@ -338,6 +352,7 @@ __description("Arena LDSX, S8")
__success __retval(-1)
__arch_x86_64
__arch_arm64
+__arch_riscv64
__naked void arena_ldsx_s8(void *ctx)
{
asm volatile (
@@ -369,6 +384,7 @@ __description("Arena LDSX, S16")
__success __retval(-1)
__arch_x86_64
__arch_arm64
+__arch_riscv64
__naked void arena_ldsx_s16(void *ctx)
{
asm volatile (
@@ -400,6 +416,7 @@ __description("Arena LDSX, S32")
__success __retval(-1)
__arch_x86_64
__arch_arm64
+__arch_riscv64
__naked void arena_ldsx_s32(void *ctx)
{
asm volatile (
--
2.50.1
_______________________________________________
linux-riscv mailing list
linux-riscv@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-riscv
^ permalink raw reply related [flat|nested] 8+ messages in thread