BPF List
 help / color / mirror / Atom feed
From: Eduard Zingerman <eddyz87@gmail.com>
To: Alexei Starovoitov <alexei.starovoitov@gmail.com>, bpf@vger.kernel.org
Cc: daniel@iogearbox.net, andrii@kernel.org, memxor@gmail.com,
	 a.s.protopopov@gmail.com
Subject: Re: [PATCH bpf-next 05/17] bpf: Add callx instruction to call bpf subprogs indirectly
Date: Wed, 23 Sep 2026 17:09:56 -0700	[thread overview]
Message-ID: <0e1bdfe95f011b5074fe9eb5306f9a5255293188.camel@gmail.com> (raw)
In-Reply-To: <20260922011323.1298619-6-alexei.starovoitov@gmail.com>

On Tue, 2026-09-22 at 01:13 +0000, Alexei Starovoitov wrote:
> From: Alexei Starovoitov <ast@kernel.org>
> 
> Introduce BPF_JMP | BPF_CALL | BPF_X (opcode 0x8d) 'callx dst_reg'
> instruction: indirect call of bpf subprog with address in dst_reg.
> That's the encoding LLVM emits for calls via function pointer.
> src_reg, off, imm are reserved and must be zero.
> 
> dst_reg must be PTR_TO_FUNC produced by ld_imm64 BPF_PSEUDO_FUNC.
> check_ld_imm() allows it for static subprogs only, so callx cannot call
> global subprogs or the main prog. Since every callee has its address
> taken by ld_imm64, add_subprogs() and check_cfg() see all of them before
> the main pass, and might_sleep, changes_pkt_data, might_throw of
> the callee are already merged into the subprog that takes the address.
> 
> reg->subprogno is the callee. Verify callx as a direct call of that
> static subprog: split check_func_call() into check_static_func_call()
> that is shared with new check_func_callx(). Different paths through
> the same callx may call different subprogs.
> 
> Arithmetic on PTR_TO_FUNC is allowed, so check that the pointer wasn't
> modified. Allow callx while holding a lock like direct calls of static
> subprogs.
> 
> The interpreter doesn't support callx. Set jit_required and add
> bpf_jit_supports_callx() for JITs to opt in. No JIT does yet, so callx
> is still rejected.
> 
> Print it as "callx rN" in the verifier log and xlated dump.
> 
> Adjust "invalid call insn1" test_verifier test that used opcode 0x8d as
> unknown opcode. It fails with "R0 !read_ok" now.
> 
> Signed-off-by: Alexei Starovoitov <ast@kernel.org>
> ---

Acked-by: Eduard Zingerman <eddyz87@gmail.com>

...

> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index 72ea662baea5..0d32d3921210 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c

...

> @@ -18725,7 +18806,8 @@ static int do_check_insn(struct bpf_verifier_env *env, bool *do_print_state)
>  
>  		env->jmps_processed++;
>  		if (opcode == BPF_CALL) {
> -			if (env->cur_state->active_locks) {
> +			/* similar to static subprog calls callx is allowed under a lock */
> +			if (env->cur_state->active_locks && !bpf_is_callx(insn)) {

Nit: moving !bpf_is_callx(insn) inside the nested 'if' would have been less surprising.

>  				if ((insn->src_reg == BPF_REG_0 &&
>  				     insn->imm != BPF_FUNC_spin_unlock &&
>  				     insn->imm != BPF_FUNC_kptr_xchg) ||

...

  reply	other threads:[~2026-09-24  0:09 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22  1:13 [PATCH bpf-next 00/17] bpf: Indirect calls of bpf subprogs (callx) Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 01/17] bpf: Fix infinite loop in check_max_stack_depth() Alexei Starovoitov
2026-09-22  2:01   ` bot+bpf-ci
2026-09-22  2:56     ` Alexei Starovoitov
2026-09-23 22:35   ` Eduard Zingerman
2026-09-22  1:13 ` [PATCH bpf-next 02/17] selftests/bpf: Test recursion through a global function and a callback Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 03/17] bpf: Don't fold loads from insn_array maps into constants Alexei Starovoitov
2026-09-23 22:39   ` Eduard Zingerman
2026-09-23 23:12     ` Alexei Starovoitov
2026-09-24  0:19   ` bot+bpf-ci
2026-09-22  1:13 ` [PATCH bpf-next 04/17] bpf: Prepare static analysis passes for callx instruction Alexei Starovoitov
2026-09-23 23:10   ` Eduard Zingerman
2026-09-23 23:51     ` Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 05/17] bpf: Add callx instruction to call bpf subprogs indirectly Alexei Starovoitov
2026-09-24  0:09   ` Eduard Zingerman [this message]
2026-09-22  1:13 ` [PATCH bpf-next 06/17] bpf: Add callx calls to the call graph Alexei Starovoitov
2026-09-22  1:27   ` sashiko-bot
2026-09-22  2:54     ` Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 07/17] bpf, x86: Add JIT support for callx Alexei Starovoitov
2026-09-22  1:27   ` sashiko-bot
2026-09-22  2:53     ` Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 08/17] bpf, arm64: " Alexei Starovoitov
2026-09-22 15:05   ` Puranjay Mohan
2026-09-22  1:13 ` [PATCH bpf-next 09/17] bpf: Discover subprogs described by func_info Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 10/17] bpf: Recognize pointers to functions in read-only maps Alexei Starovoitov
2026-09-22  1:31   ` sashiko-bot
2026-09-22  3:01     ` Alexei Starovoitov
2026-09-24  0:46   ` bot+bpf-ci
2026-09-24  2:12     ` Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 11/17] libbpf: Support pointers to static functions in data when linking Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 12/17] libbpf: Resolve pointers to functions in read-only data Alexei Starovoitov
2026-09-24  0:33   ` bot+bpf-ci
2026-09-24  2:13     ` Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 13/17] libbpf: Treat .data.rel.ro as " Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 14/17] libbpf: Support pointers to functions in read-only data in light skeleton Alexei Starovoitov
2026-09-22  2:01   ` bot+bpf-ci
2026-09-22  2:55     ` Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 15/17] selftests/bpf: Add tests for callx Alexei Starovoitov
2026-09-24  0:33   ` bot+bpf-ci
2026-09-24  2:13     ` Alexei Starovoitov
2026-09-22  1:13 ` [PATCH bpf-next 16/17] selftests/bpf: Add tests for callx through pointers in read-only data Alexei Starovoitov
2026-09-22  2:01   ` bot+bpf-ci
2026-09-24  0:33   ` bot+bpf-ci
2026-09-22  1:13 ` [PATCH bpf-next 17/17] bpf, docs: Document callx instruction Alexei Starovoitov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=0e1bdfe95f011b5074fe9eb5306f9a5255293188.camel@gmail.com \
    --to=eddyz87@gmail.com \
    --cc=a.s.protopopov@gmail.com \
    --cc=alexei.starovoitov@gmail.com \
    --cc=andrii@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=memxor@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox