BPF List
 help / color / mirror / Atom feed
From: Yonghong Song <yonghong.song@linux.dev>
To: Eduard Zingerman <eddyz87@gmail.com>, bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
	Andrii Nakryiko <andrii@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
	kernel-team@fb.com
Subject: Re: [PATCH bpf-next v5 07/21] bpf: Explore the landing pads no call site reaches
Date: Wed, 23 Sep 2026 10:27:29 -0700	[thread overview]
Message-ID: <3469ede8-6c37-49c9-b261-d2c8506eada5@linux.dev> (raw)
In-Reply-To: <df24934c5ecbd70bc35b528b8e58ae668ce02051.camel@gmail.com>



On 9/23/26 9:26 AM, Eduard Zingerman wrote:
> On Tue, 2026-09-22 at 21:59 -0700, Yonghong Song wrote:
>> A cleanup record need not cover a call an exception can unwind out of: a
>> frontend is free to emit a region around a helper or an ordinary kfunc,
>> both nounwind here. Nothing marks a call site then, and that record's
>> landing pad is reached by nothing at all -- leaving bpf_check_cfg() to
>> refuse the program over code its own frontend had no way not to emit:
>>
>>     0: call bpf_preempt_disable
>>     1: call bpf_preempt_enable      record = { begin = 1, end = 2, pad = 4 }
>>     2: r0 = 0
>>     3: exit
>>     4: r1 = pads_ran ll             landing pad
>>     6: r2 = *(u64 *)(r1 + 0)
>>     7: r2 |= RAN_NOUNWIND_REC
>>     8: *(u64 *)(r1 + 0) = r2
>>     9: call bpf_unwind_resume
>>    10: exit
>>
>> The range [1,2) holds one call, and it is a kfunc, so an exception cannot
>> come out of it. mark_call_sites() marks nothing, nothing pushes an edge to
>> 4, and 4 through 10 are reachable from nothing: "unreachable insn 4". The
>> pad is dead, which is correct -- no exception can ever arrive at it -- but
>> the program is fine and has to load.
>>
>> Walk every pad the table names that the edges did not reach, the way the
>> walk is already re-seeded at an exception callback. From there the pad is
>> code like any other: do_check() never enters it, because no call site
>> dispatches to it, so the dead code sweep removes it along with everything
>> else that was not reached.
>>
>> Signed-off-by: Yonghong Song <yonghong.song@linux.dev>
>> ---
> Yonghong, in v4 you said that rustc does not generate dead landing pads.
> Why do we need this patch?

This patch is to avoid a verification failure. Let us say, we remove this
patch and run the following
   ./test_progs -t exceptions_cleanup
and we will get the following failure:

test_exceptions_cleanup:PASS:open 0 nsec
test_light_skeleton:PASS:light open_and_load 0 nsec
test_light_skeleton:PASS:run 0 nsec
test_light_skeleton:PASS:retval 0 nsec
test_light_skeleton:PASS:pads_ran 0 nsec
libbpf: prog 'entry_nounwind_rec': BPF program load failed: -EINVAL
libbpf: prog 'entry_nounwind_rec': -- BEGIN PROG LOAD LOG --
unreachable insn 6

Verification failed: Program Structure: Unreachable instruction

Reason:
   Instruction 6 is not reachable from the program entry point.

At:
   nounwind_rec_frame @ exceptions_cleanup_shapes.c:663:2
   Source context:
       661 | ...
       662 | ...
   >>> 663 |         asm volatile (
           |         ^-- error: unreachable instruction
       664 | ...
       665 | ...
   Instruction context:
        4 | (b7) r0 = 0
        5 | (95) exit
   >>>  6 | (18) r1 = 0xffa0000001d94010
        8 | (79) r2 = *(u64 *)(r1 +0)

Suggestion:
   Remove the unreachable instruction or add valid control flow that reaches it.

processed 0 insns (limit 1000000) max_states_per_insn 0 total_states 0 peak_states 0 mark_read 0
-- END PROG LOAD LOG --
libbpf: prog 'entry_nounwind_rec': failed to load: -EINVAL
libbpf: failed to load object 'exceptions_cleanup_shapes'
libbpf: failed to load BPF skeleton 'exceptions_cleanup_shapes': -EINVAL
test_shapes:FAIL:shapes open_and_load unexpected error: -22
tester_init:PASS:tester_log_buf 0 nsec
process_subtest:PASS:obj_open_mem 0 nsec
process_subtest:PASS:specs_alloc 0 nsec
#128/4   exceptions_cleanup/light_skeleton:FAIL
#128     exceptions_cleanup:FAIL

This happens in cfg.c:

         for (i = 0; i < insn_cnt; i++) {
                 struct bpf_insn *insn = &env->prog->insnsi[i];
                         
                 if (insn_state[i] != EXPLORED) {
                         verbose(env, "unreachable insn %d\n", i);
                         bpf_diag_program_structure(
                                 env, i, "unreachable instruction",
                                 "Remove the unreachable instruction or add valid control flow that reaches it.",
                                 "Instruction %d is not reachable from the program entry point.", i);
                         ret = -EINVAL;
                         goto err_free;
                 }
                 if (bpf_is_ldimm64(insn)) {
                         if (insn_state[i + 1] != 0) {
                                 verbose(env, "jump into the middle of ldimm64 insn %d\n", i);
                                 bpf_diag_program_structure(
                                         env, i, "jump into ldimm64 immediate",
                                         "Target the first instruction of the ldimm64 pair, or restructure the jump target.",
                                         "Control flow reaches the second half of the ldimm64 instruction pair that starts at instruction %d.",
                                         i);
                                 ret = -EINVAL;
                                 goto err_free;
                         }
                         i++; /* skip second half of ldimm64 */
                 }
         }

This patch intends to explore *unreachable* insns to avoid verification failure.

I think due to "record = { begin = 1, end = 2, pad = 4 }", it is considered that the code at 'pad = 4'
is not dead, but actually it does dead later so we have the above failure.

So I add this patch to avoid failure. But maybe we should just remove this patch,
and mark this test as failure as indeed landing pad is not reachable.

WDYT?


  reply	other threads:[~2026-09-23 17:27 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23  4:58 [PATCH bpf-next v5 00/21] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Yonghong Song
2026-09-23  4:58 ` [PATCH bpf-next v5 01/21] bpf: Pack bpf_insn_aux_data flags into bit fields Yonghong Song
2026-09-23  5:40   ` bot+bpf-ci
2026-09-23 19:16   ` Eduard Zingerman
2026-09-23  4:58 ` [PATCH bpf-next v5 02/21] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 03/21] bpf: Add the bpf_unwind_resume() kfunc Yonghong Song
2026-09-23  6:13   ` Kumar Kartikeya Dwivedi
2026-09-23  4:59 ` [PATCH bpf-next v5 04/21] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 05/21] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-23  5:40   ` bot+bpf-ci
2026-09-23  4:59 ` [PATCH bpf-next v5 06/21] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-23  5:51   ` bot+bpf-ci
2026-09-23 19:25   ` Eduard Zingerman
2026-09-23  4:59 ` [PATCH bpf-next v5 07/21] bpf: Explore the landing pads no call site reaches Yonghong Song
2026-09-23 16:26   ` Eduard Zingerman
2026-09-23 17:27     ` Yonghong Song [this message]
2026-09-23 18:06       ` Eduard Zingerman
2026-09-23 18:09         ` Yonghong Song
2026-09-23 21:28     ` Alexei Starovoitov
2026-09-23 22:19       ` Eduard Zingerman
2026-09-23 23:20         ` Alexei Starovoitov
2026-09-24  0:13           ` Kumar Kartikeya Dwivedi
2026-09-24  1:53             ` Alexei Starovoitov
2026-09-24  6:12               ` Kumar Kartikeya Dwivedi
2026-09-23 23:09       ` Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 08/21] bpf: Walk the exception unwind in the verifier Yonghong Song
2026-09-23 16:34   ` Eduard Zingerman
2026-09-23 18:01     ` Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 09/21] bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 10/21] bpf: Refuse a private stack for a program with an exception cleanup table Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 11/21] bpf: Dispatch exception cleanup pads from bpf_throw() Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 12/21] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-23  6:45   ` Eduard Zingerman
2026-09-23 20:45     ` Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 13/21] bpf, arm64: " Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 14/21] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-23  8:36   ` Kumar Kartikeya Dwivedi
2026-09-23  5:00 ` [PATCH bpf-next v5 15/21] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-23  5:00 ` [PATCH bpf-next v5 16/21] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-23  5:52   ` Kumar Kartikeya Dwivedi
2026-09-23  5:00 ` [PATCH bpf-next v5 17/21] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-23  5:00 ` [PATCH bpf-next v5 18/21] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-23  5:40   ` bot+bpf-ci
2026-09-23  5:00 ` [PATCH bpf-next v5 19/21] selftests/bpf: Add an end-to-end .bpf_cleanup exception test Yonghong Song
2026-09-23  5:51   ` bot+bpf-ci
2026-09-23  5:00 ` [PATCH bpf-next v5 20/21] selftests/bpf: Cover the exception cleanup shapes the chain does not reach Yonghong Song
2026-09-23  5:51   ` bot+bpf-ci
2026-09-23  7:50   ` Eduard Zingerman
2026-09-23  5:00 ` [PATCH bpf-next v5 21/21] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3469ede8-6c37-49c9-b261-d2c8506eada5@linux.dev \
    --to=yonghong.song@linux.dev \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=kernel-team@fb.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox