From: Yonghong Song <yonghong.song@linux.dev>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
kernel-team@fb.com
Subject: [PATCH bpf-next v4 10/15] bpf, x86: Move kfunc arguments into the x86-64 calling convention
Date: Sat, 12 Sep 2026 12:52:47 -0700 [thread overview]
Message-ID: <20260912195247.989857-1-yonghong.song@linux.dev> (raw)
In-Reply-To: <20260912195156.980886-1-yonghong.song@linux.dev>
The x86-64 allows 6 register arguments and then stack arguments, but
backfilling the 6th register is possible, as in the following example:
/* s is a 16-byte struct */
void kfunc(u64 a, u64 b, u64 c, u64 d, u64 e, struct big s, u64 f)
BPF puts s in slots 5 and 6, R9 and the first stack slot, and f in slot
7, while x86-64 puts s in the two stack slots and f in R9. Emit the
moves bpf_jit_plan_arg_moves() plans to bridge the two.
Only one argument ever moves down, as an argument frees one register at
most, so carrying that single value in the scratch register past its own
destination is enough.
In addition, the arena argument walk counts eightbytes rather than
parameters, as an argument may take two registers.
Signed-off-by: Yonghong Song <yonghong.song@linux.dev>
---
arch/x86/net/bpf_jit_comp.c | 78 +++++++++++++++++++++++++++++++++++--
1 file changed, 75 insertions(+), 3 deletions(-)
diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
index bba351944202..2671e4118d00 100644
--- a/arch/x86/net/bpf_jit_comp.c
+++ b/arch/x86/net/bpf_jit_comp.c
@@ -1839,6 +1839,65 @@ static int emit_spectre_bhb_barrier(u8 **pprog, u8 *ip,
return 0;
}
+static const struct bpf_jit_arg_abi x86_arg_abi = {
+ .nr_arg_regs = 6,
+ .backfill_after_stack = true,
+ .even_stack_align = true,
+};
+
+static const u8 x86_arg_reg[] = {
+ BPF_REG_1, BPF_REG_2, BPF_REG_3, BPF_REG_4, BPF_REG_5, X86_REG_R9,
+};
+
+/*
+ * Move the arguments the x86-64 ABI places somewhere other than the argument
+ * slot the BPF calling convention gave them. @stack_base addresses the
+ * outgoing stack argument area from RBP. Return the number of emitted bytes.
+ */
+static int emit_kfunc_arg_moves(const struct btf_func_model *fm, s32 stack_base, u8 **pprog)
+{
+ struct bpf_jit_arg_move moves[BPF_JIT_MAX_ARG_MOVES];
+ const u8 nreg = x86_arg_abi.nr_arg_regs;
+ u8 *prog = *pprog, *start = prog;
+ u32 i, n;
+
+ n = bpf_jit_plan_arg_moves(&x86_arg_abi, fm, moves);
+
+ for (i = 0; i < n; i++) {
+ u8 dst = moves[i].dst, src = moves[i].src, reg;
+ bool dst_mem = dst != BPF_JIT_ARG_TMP && dst >= nreg;
+ bool src_mem = src != BPF_JIT_ARG_TMP && src >= nreg;
+
+ /*
+ * Take the value into a register: the one it belongs in, the
+ * scratch when it is carried past its own destination, and
+ * BPF_REG_AX only to pass one stack slot to another.
+ */
+ if (src == BPF_JIT_ARG_TMP) {
+ reg = AUX_REG;
+ } else if (src_mem) {
+ reg = dst == BPF_JIT_ARG_TMP ? AUX_REG :
+ dst_mem ? BPF_REG_AX : x86_arg_reg[dst];
+ emit_ldx(&prog, BPF_DW, reg, BPF_REG_FP,
+ stack_base + (src - nreg) * 8);
+ } else {
+ reg = x86_arg_reg[src];
+ }
+
+ /* And leave it where the argument belongs. */
+ if (dst == BPF_JIT_ARG_TMP)
+ emit_mov_reg(&prog, true, AUX_REG, reg);
+ else if (dst_mem)
+ emit_stx(&prog, BPF_DW, BPF_REG_FP, reg,
+ stack_base + (dst - nreg) * 8);
+ else if (reg != x86_arg_reg[dst])
+ emit_mov_reg(&prog, true, x86_arg_reg[dst], reg);
+ }
+
+ *pprog = prog;
+ return prog - start;
+}
+
/*
* Rebase the __arena args of a kfunc call to arena kernel addresses,
* rN = kern_vm_start + (u32)rN, with R12 holding kern_vm_start. A nullable
@@ -1850,11 +1909,17 @@ static int emit_kfunc_arena_args(struct bpf_prog *bpf_prog,
{
u8 *prog = *pprog;
u8 *start = prog;
- int i;
+ int i, slot;
- for (i = 0; i < min_t(int, fm->nr_args, MAX_BPF_FUNC_REG_ARGS); i++) {
+ for (i = 0, slot = 0; i < fm->nr_args; i++) {
+ u32 arg_regs = (fm->arg_size[i] + 7) / 8;
u8 flags = fm->arg_flags[i];
- u32 reg = BPF_REG_1 + i;
+ u32 reg;
+
+ if (slot + arg_regs > MAX_BPF_FUNC_REG_ARGS)
+ break;
+ reg = BPF_REG_1 + slot;
+ slot += arg_regs;
if (!(flags & BTF_FMODEL_ARENA_ARG))
continue;
@@ -2837,6 +2902,8 @@ static int do_jit(struct bpf_verifier_env *env, struct bpf_prog *bpf_prog, int *
if (err < 0)
return err;
ip += err;
+ ip += emit_kfunc_arg_moves(fm, outgoing_arg_base -
+ outgoing_rsp, &prog);
}
if (priv_frame_ptr) {
push_r9(&prog);
@@ -4351,6 +4418,11 @@ bool bpf_jit_supports_kfunc_ret_reg_pair(void)
return true;
}
+const struct bpf_jit_arg_abi *bpf_jit_arg_abi(void)
+{
+ return &x86_arg_abi;
+}
+
bool bpf_jit_supports_stack_args(void)
{
return true;
--
2.53.0-Meta
next prev parent reply other threads:[~2026-09-12 19:52 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-12 19:51 [PATCH bpf-next v4 00/15] bpf: Support by-value struct and __int128 arguments Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 01/15] bpf: Read a kfunc's __sz argument only when it is in a register Yonghong Song
2026-09-12 20:06 ` sashiko-bot
2026-09-13 2:40 ` Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 02/15] selftests/bpf: Add a test for an __int128 by-value argument Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 03/15] bpf: Rename bpf_subprog_info::arg_cnt to arg_slot_cnt Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 04/15] bpf: Index global function arguments by argument slot Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 05/15] bpf: Support by-value struct arguments up to 16 bytes Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 06/15] bpf: Support __int128 as a by-value function argument Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 07/15] bpf: Rename bpf_call_summary::num_params to arg_slot_cnt Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 08/15] bpf: Recognize by-value struct and __int128 kfunc arguments Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 09/15] bpf: Prepare kfunc arguments for the JIT from an ABI description Yonghong Song
2026-09-12 20:10 ` sashiko-bot
2026-09-12 19:52 ` Yonghong Song [this message]
2026-09-12 19:52 ` [PATCH bpf-next v4 11/15] bpf, arm64: Place trampoline arguments by the arm64 calling convention Yonghong Song
2026-09-13 2:47 ` Yonghong Song
2026-09-12 19:52 ` [PATCH bpf-next v4 12/15] bpf, arm64: Move kfunc arguments into " Yonghong Song
2026-09-12 19:53 ` [PATCH bpf-next v4 13/15] selftests/bpf: Add C tests for by-value arguments up to 16 bytes Yonghong Song
2026-09-12 19:53 ` [PATCH bpf-next v4 14/15] selftests/bpf: Add inline-asm tests for by-value arguments Yonghong Song
2026-09-12 19:53 ` [PATCH bpf-next v4 15/15] selftests/bpf: Add tests for by-value kfunc arguments Yonghong Song
2026-09-13 4:00 ` [PATCH bpf-next v4 00/15] bpf: Support by-value struct and __int128 arguments patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260912195247.989857-1-yonghong.song@linux.dev \
--to=yonghong.song@linux.dev \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=kernel-team@fb.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox