BPF List
 help / color / mirror / Atom feed
From: Puranjay Mohan <puranjay@kernel.org>
To: bpf@vger.kernel.org
Cc: Puranjay Mohan <puranjay@kernel.org>,
	"Alexei Starovoitov" <ast@kernel.org>,
	"Daniel Borkmann" <daniel@iogearbox.net>,
	"Andrii Nakryiko" <andrii@kernel.org>,
	"Martin KaFai Lau" <martin.lau@linux.dev>,
	"Eduard Zingerman" <eddyz87@gmail.com>,
	"Kumar Kartikeya Dwivedi" <memxor@gmail.com>,
	"Song Liu" <song@kernel.org>,
	"Yonghong Song" <yonghong.song@linux.dev>,
	Xu Kuohai <xukuohai@huaweicloud.com>,
	Mark Rutland <mark.rutland@arm.com>,
	Will Deacon <will@kernel.org>,
	Catalin Marinas <catalin.marinas@arm.com>
Subject: [PATCH bpf-next 0/7] bpf, arm64: __arena kfunc and struct_ops arguments
Date: Mon, 10 Aug 2026 12:09:13 -0700	[thread overview]
Message-ID: <20260810190922.3408757-1-puranjay@kernel.org> (raw)

The x86-64 JIT recently gained support for the __arena and
__arena__nullable argument suffixes on kfuncs and struct_ops stubs. This
adds the arm64 side and flips bpf_jit_supports_arena_args() on, so the
verifier stops rejecting these programs on arm64.

Patch 1 is an independent fix. save_args() reads stack-passed arguments
at FP + 32, which only holds when the trampoline is entered through the
fentry call and two frame records are pushed. A struct_ops trampoline is
entered via blr and pushes one frame fewer, so its stack arguments start
at FP + 16 and every one of them was read two slots off. No struct_ops
member passed arguments on the stack until the test added by commit
2d4de9a493a0, which is why this went unnoticed. It carries a Fixes tag
and can be taken separately; note that the test covering it only runs on
arm64 once the rest of this series lands.

Patch 2 adds an ADD/SUB (extended register) encoder to the insn library,
so the JIT can zero-extend and add in one instruction.

Patches 3 and 4 are the JIT work. A kfunc argument is rebased onto the
arena base at the call site:

        add     xN, x28, wN, uxtw

and a nullable one skips the add so NULL stays NULL:

        mov     wN, wN
        cbz     wN, 1f
        add     xN, x28, wN, uxtw
1:

A struct_ops callback converts in the other direction, in the trampoline
while saving arguments into the BPF ctx, with the low half of the arena
base kept in x11:

        sub     w10, wsrc, w11
        str     x10, [sp, #slot]

Patches 5 and 6 add arm64 JIT-sequence assertions and drop the x86-64
gating from the existing arena argument tests. Patch 7 is arch-neutral:
it adds a struct_ops member whose first argument is a 16-byte struct
passed by value, so the arena pointer does not land at the ctx slot its
argument index suggests. Nothing covered that before, and it is the case
patch 4 has to get right.

Puranjay Mohan (6):
  bpf, arm64: Fix stack-passed arguments for indirect trampolines
  bpf, arm64: JIT __arena kfunc argument rebasing
  bpf, arm64: Convert struct_ops arena arguments in the trampoline
  selftests/bpf: Add arm64 JIT-sequence tests for __arena kfunc
    arguments
  selftests/bpf: Enable __arena argument tests on arm64
  selftests/bpf: Test a multi-slot argument before a struct_ops arena
    argument

Tejun Heo (1):
  arm64: insn: Add encoder for ADD/SUB (extended register)

 Documentation/bpf/kfuncs.rst                  |   6 +-
 arch/arm64/include/asm/insn.h                 |  23 +++
 arch/arm64/lib/insn.c                         |  60 ++++++++
 arch/arm64/net/bpf_jit.h                      |  11 ++
 arch/arm64/net/bpf_jit_comp.c                 | 140 +++++++++++++++---
 .../bpf/prog_tests/test_struct_ops_arena.c    |  10 +-
 .../testing/selftests/bpf/progs/arena_kfunc.c |   9 ++
 .../selftests/bpf/progs/arena_kfunc_jit.c     |  20 +++
 .../selftests/bpf/progs/struct_ops_arena.c    |  24 +++
 .../selftests/bpf/test_kmods/bpf_testmod.c    |  15 ++
 .../selftests/bpf/test_kmods/bpf_testmod.h    |   8 +
 .../bpf/test_kmods/bpf_testmod_kfunc.h        |   1 +
 12 files changed, 301 insertions(+), 26 deletions(-)


base-commit: d114bb98936770c501c958bf2bc5fb6b7c0bad7b
-- 
2.53.0-Meta


             reply	other threads:[~2026-08-10 19:09 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-10 19:09 Puranjay Mohan [this message]
2026-08-10 19:09 ` [PATCH bpf-next 1/7] bpf, arm64: Fix stack-passed arguments for indirect trampolines Puranjay Mohan
2026-08-10 19:09 ` [PATCH bpf-next 2/7] arm64: insn: Add encoder for ADD/SUB (extended register) Puranjay Mohan
2026-08-10 19:19   ` sashiko-bot
2026-08-10 19:09 ` [PATCH bpf-next 3/7] bpf, arm64: JIT __arena kfunc argument rebasing Puranjay Mohan
2026-08-10 19:09 ` [PATCH bpf-next 4/7] bpf, arm64: Convert struct_ops arena arguments in the trampoline Puranjay Mohan
2026-08-10 19:09 ` [PATCH bpf-next 5/7] selftests/bpf: Add arm64 JIT-sequence tests for __arena kfunc arguments Puranjay Mohan
2026-08-10 19:09 ` [PATCH bpf-next 6/7] selftests/bpf: Enable __arena argument tests on arm64 Puranjay Mohan
2026-08-10 19:09 ` [PATCH bpf-next 7/7] selftests/bpf: Test a multi-slot argument before a struct_ops arena argument Puranjay Mohan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260810190922.3408757-1-puranjay@kernel.org \
    --to=puranjay@kernel.org \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=mark.rutland@arm.com \
    --cc=martin.lau@linux.dev \
    --cc=memxor@gmail.com \
    --cc=song@kernel.org \
    --cc=will@kernel.org \
    --cc=xukuohai@huaweicloud.com \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox