BPF List
 help / color / mirror / Atom feed
From: Eduard Zingerman <eddyz87@gmail.com>
To: Alexei Starovoitov <alexei.starovoitov@gmail.com>,
	Kumar Kartikeya Dwivedi <memxor@gmail.com>
Cc: Yonghong Song <yonghong.song@linux.dev>,
	bpf@vger.kernel.org, Alexei Starovoitov <ast@kernel.org>,
	Andrii Nakryiko <andrii@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
		kernel-team@fb.com
Subject: Re: [PATCH bpf-next v4 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds
Date: Tue, 22 Sep 2026 23:16:21 -0700	[thread overview]
Message-ID: <16a889ab8ae491155ca962bf2e14e83e1f921cf3.camel@gmail.com> (raw)
In-Reply-To: <DLMFEI43TYVI.1KNMAQLNWT2JC@gmail.com>

On Wed, 2026-09-23 at 04:54 +0000, Alexei Starovoitov wrote:
> On Wed Sep 23, 2026 at 4:36 AM UTC, Kumar Kartikeya Dwivedi wrote:
> > 
> > You can obviously insert aborts at any point in the program, provided
> > such a primitive works, even when the compiler doesn't see it. It is
> > just a way to halt program execution along a given path, and has
> > plenty of precedents (assert(false), std::terminate(), panic!() =
> > abort). That property can be used for several purposes, including
> > proving a condition true on the other path that does not abort, and
> > retaining that path condition throughout the rest of the program. That
> > is basically the gist of Eduard's suggestion.
> 
> That's only true for user space.
> For bpf progs there is no such primitive. bpf_throw() is not it.
> We cannot make it work from arbitrary places without introducing
> massive verifier debt for automatic creation of exception tables
> or via equally massive runtime penalty to remember all things to cleanup.

I'm not sure that automatic exception tables would be all that more
complex, current implementation is not that trivial either.
Plus you mention LLMs-the-almighty yourself.

But speaking of runtime costs.
For a program like this:

  main:
    a()
  a:
    b()
  b:
    throw()

The series currently generates push r6-r9 at entry to each function.
This is needed to recover r6-r9 for the landing pads.
See the program and disassembly below.
Do we want to address this somehow, or is the idea that for complex
subprograms the sequence would amortize away?
On x86 the information about registers location at throw/landing-pad-entry
is stored in .eh_frame section, as far as I understand.

BPF:

  jit_probe_b:
	r1 = 32;
  1:	call bpf_throw;
  2:	r0 = 0;
	exit;
  3:	call bpf_unwind_resume;
	exit;
	CLEANUP_REC(1b, 2b, 3b)

  jit_probe_a:
	r6 = 0x1234;
  1:	call jit_probe_b;
  2:	r0 = 0;
	exit;
  3:	r1 = r6;
	call bpf_unwind_resume;
	exit;
	CLEANUP_REC(1b, 2b, 3b)

  jit_probe_main:
	jit_probe_a();
	return 0;

x86:

  jit_probe_main:
    0:	endbr64
    4:	nopl	(%rax,%rax)
    9:	nopl	(%rax)
    c:	pushq	%rbp
    d:	movq	%rsp, %rbp
    10:	endbr64
    14:	pushq	%r12
    16:	pushq	%rbx
    17:	pushq	%r13
    19:	pushq	%r14
    1b:	pushq	%r15
    1d:	callq	0x30
  
  jit_probe_a:
    0:	endbr64
    4:	nopl	(%rax,%rax)
    9:	nopl	(%rax)
    c:	pushq	%rbp
    d:	movq	%rsp, %rbp
    10:	endbr64
    14:	pushq	%r12
    16:	pushq	%rbx
    17:	pushq	%r13
    19:	pushq	%r14
    1b:	pushq	%r15
    1d:	movl	$0x1234, %ebx
    22:	callq	0x9c
    27:	endbr64
    2b:	movq	%rbx, %rdi
    2e:	retq
    
  jit_probe_b:
    0:	endbr64
    4:	nopl	(%rax,%rax)
    9:	nopl	(%rax)
    c:	pushq	%rbp
    d:	movq	%rsp, %rbp
    10:	endbr64
    14:	subq	$0x28, %rsp
    1b:	pushq	%r12
    1d:	pushq	%rbx
    1e:	pushq	%r13
    20:	pushq	%r14
    22:	pushq	%r15
    24:	movl	$0x20, %edi
    29:	movq	%r15, -0x28(%rbp)
    2d:	movq	%r14, -0x20(%rbp)
    31:	movq	%r13, -0x18(%rbp)
    35:	movq	%rbx, -0x10(%rbp)
    39:	movq	%r12, -0x8(%rbp)
    3d:	callq	0xffffffffe18c5c5c
    42:	endbr64
    46:	retq

...

  parent reply	other threads:[~2026-09-23  6:16 UTC|newest]

Thread overview: 80+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 21:00 [PATCH bpf-next v4 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 01/20] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:27     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 02/20] bpf: Add the bpf_unwind_resume() kfunc Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:31     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 03/20] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-22  4:04   ` Alexei Starovoitov
2026-09-22  5:28     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 04/20] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-22 18:27   ` Eduard Zingerman
2026-09-23  3:07     ` Yonghong Song
2026-09-23  3:54       ` Eduard Zingerman
2026-09-23  4:05         ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 05/20] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 06/20] bpf: Explore the landing pads no call site reaches Yonghong Song
2026-09-21 23:58   ` Eduard Zingerman
2026-09-22  3:32     ` Yonghong Song
2026-09-22  4:10       ` Eduard Zingerman
2026-09-21 21:01 ` [PATCH bpf-next v4 07/20] bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch Yonghong Song
2026-09-21 21:20   ` sashiko-bot
2026-09-22  3:39     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:44     ` Yonghong Song
2026-09-22  0:30   ` Eduard Zingerman
2026-09-22  3:45     ` Yonghong Song
2026-09-22 21:43       ` Eduard Zingerman
2026-09-23  3:11         ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 08/20] bpf: Walk the exception unwind in the verifier Yonghong Song
2026-09-21 21:40   ` sashiko-bot
2026-09-22  4:17     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  5:21     ` Yonghong Song
2026-09-22  4:08   ` Alexei Starovoitov
2026-09-22  5:25     ` Yonghong Song
2026-09-22 21:53       ` Eduard Zingerman
2026-09-23  3:18         ` Yonghong Song
2026-09-22 23:43   ` Eduard Zingerman
2026-09-23  3:21     ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 09/20] bpf: Refuse a private stack for a program with an exception cleanup table Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 10/20] bpf: Dispatch exception cleanup pads from bpf_throw() Yonghong Song
2026-09-22 21:38   ` Eduard Zingerman
2026-09-23  3:22     ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 11/20] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 12/20] bpf, arm64: " Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 13/20] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-21 21:13   ` sashiko-bot
2026-09-21 21:01 ` [PATCH bpf-next v4 14/20] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 15/20] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-21 21:20   ` sashiko-bot
2026-09-21 21:01 ` [PATCH bpf-next v4 16/20] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-21 21:02 ` [PATCH bpf-next v4 17/20] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-21 21:02 ` [PATCH bpf-next v4 18/20] selftests/bpf: Add an end-to-end .bpf_cleanup exception test Yonghong Song
2026-09-21 21:22   ` sashiko-bot
2026-09-22  5:26     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-21 21:02 ` [PATCH bpf-next v4 19/20] selftests/bpf: Cover the exception cleanup shapes the chain does not reach Yonghong Song
2026-09-21 21:19   ` sashiko-bot
2026-09-21 21:02 ` [PATCH bpf-next v4 20/20] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
2026-09-22  1:08 ` [PATCH bpf-next v4 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Eduard Zingerman
2026-09-22  2:16   ` Alexei Starovoitov
2026-09-22  2:31     ` Kumar Kartikeya Dwivedi
2026-09-22 21:44       ` Alexei Starovoitov
2026-09-23  4:36         ` Kumar Kartikeya Dwivedi
2026-09-23  4:54           ` Alexei Starovoitov
2026-09-23  5:20             ` Kumar Kartikeya Dwivedi
2026-09-23  6:16             ` Eduard Zingerman [this message]
2026-09-23  6:44               ` Kumar Kartikeya Dwivedi
2026-09-22  4:27     ` Eduard Zingerman
2026-09-22 21:47       ` Alexei Starovoitov
2026-09-22 23:08         ` Eduard Zingerman
2026-09-22 23:37           ` Alexei Starovoitov
2026-09-23  0:04             ` Eduard Zingerman
2026-09-23 19:04               ` Eduard Zingerman
2026-09-23 19:24                 ` Andrii Nakryiko
2026-09-23 19:34                   ` Kumar Kartikeya Dwivedi
2026-09-23 21:34                     ` Alexei Starovoitov
2026-09-23 22:00                       ` Eduard Zingerman
2026-09-23 23:22                         ` Alexei Starovoitov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=16a889ab8ae491155ca962bf2e14e83e1f921cf3.camel@gmail.com \
    --to=eddyz87@gmail.com \
    --cc=alexei.starovoitov@gmail.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=kernel-team@fb.com \
    --cc=memxor@gmail.com \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox