BPF List
 help / color / mirror / Atom feed
From: Eduard Zingerman <eddyz87@gmail.com>
To: Alexei Starovoitov <alexei.starovoitov@gmail.com>,
	Yonghong Song <yonghong.song@linux.dev>,
	bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
	Andrii Nakryiko <andrii@kernel.org>,
	 Daniel Borkmann <daniel@iogearbox.net>,
	kernel-team@fb.com
Subject: Re: [PATCH bpf-next v4 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds
Date: Mon, 21 Sep 2026 21:27:21 -0700	[thread overview]
Message-ID: <7eba4eb055e15d5c78f463d013fa98bb21d7b494.camel@gmail.com> (raw)
In-Reply-To: <DLLHFJDS6G5L.2B273FIKF9A09@gmail.com>

On Tue, 2026-09-22 at 02:16 +0000, Alexei Starovoitov wrote:
> On Tue Sep 22, 2026 at 1:08 AM UTC, Eduard Zingerman wrote:
> > On Mon, 2026-09-21 at 14:00 -0700, Yonghong Song wrote:
> > 
> > ...
> > 
> > > Design
> > > ======
> > > 
> > > A pad is run, not lowered. bpf_throw() already walks the frames with
> > > arch_bpf_stack_walk(); it now looks each frame's return address up in
> > > that (sub)program's table and calls the pad as a subroutine of the walker,
> > > with the unwinding frame's frame pointer and its callee-saved registers
> > > restored from the spill its callee's prologue left. The pad therefore sees
> > > its own frame but runs on the walker's stack, far below it, so nothing it
> > > calls can disturb the frame it is cleaning up after. The JIT turns its
> > > bpf_unwind_resume() into the way back to the walker.
> > > 
> > > The verifier walks the same thing, step for step, so the resource rules
> > > are unchanged: whatever a pad releases is released in the verifier state
> > > too, and check_resource_leak() simply moves from "a throw was seen" to the
> > > end of the walk.
> > 
> > I have two high-level questions.
> > 
> > 1) The tables handling mechanics adds quite a lot of code to the
> >    libbpf and initial verification phases, while at the IR level
> >    it is basically an encoding for the invoke instruction:
> > 
> >      invoke <target-function>
> >          to label <where-to-go-on-return>
> >      unwind label <where-to-go-on-unwind>
> > 
> >    For the sake of discussion, wouldn't it be simpler for us to
> >    just add a 16-byte invoke instruction:
> > 
> >     word #0:
> >       code     INVOKE
> >       dst_reg  0
> >       src_reg  BPF_PSEUDO_CALL or BPF_PSEUDO_KFUNC_CALL
> >       off      existing call meaning, including kfunc BTF fd index
> >       imm      existing call-target encoding
> > 
> >     word #1:
> >       code, dst_reg, src_reg, off = 0
> >       imm      signed unwind displacement, measured in 8-byte slots
> > 
> >    With an assumption that during normal execution (not unwinding)
> >    upon return from invoke the control flow goes to a fallthrough
> >    instruction.
> > 
> >    The pros are:
> >    - much less frontend code
> >    - if in the future we would like to manipulate BPF program
> >      byte code, it would be significantly simpler to do in such form.
> 
> I think the amount of code will increase a lot more with such approach.
> All existing call flavors and my new callx would need to wrapped
> with this new 'invoke' insn.
> Also rust generates begin/end across more than single insn.

Total size of executable sections for all Meta BPF object files used
for CI veristat testing is 10Mb. Of these there are 30K non-helper
call instructions in total.
So we are talking about increase by 8 * 30K = 240K ~ 2.4% worst case.
Note that the instruction encoding optimized for size already hearts
us in src/dst registers department: we have no room for virtual
registers, which would have simplified e.g. register allocation task
for ARM64. Point being that optimizing intermediate IR for size is not
always a right target.

> >    [1] https://llvm.org/docs/LangRef.html#i-invoke
> > 
> > 2) The final goal of the BPF/Rust project is to consume whatever code
> >    rustc generates. Ultimately, this would require supporting a way
> >    to introduce runtime checks at arbitrary locations, whenever the
> >    verifier can't infer that the program is safe. 
> 
> so far all rustc code looks clean and definitely not arbitrary.
> 
> > Such checks won't
> >    necessarily have associated landing pads. Meaning that the unwinding
> 
> no landing pad? what? That's not rustc.
> You're talking about some random compiler that throws garbage.
> 
> >    logic will have to be dynamic as in exceptions part #2 sense discussed
> >    way back (2022?).
> > 
> >    The argument against exceptions part #2 back then was that the code
> >    is complex. Given the current environment, I don't think the argument
> >    still holds.
> > 
> >    Hence, given that dynamic abort would be necessary, and that the kernel's
> >    rust code is already compiled with -Cpanic=abort, do we need this static
> >    form of exceptions handling at all?
> 
> This patch is static exception handling for cases where compiler generated them.
> 
> We don't know and don't care what is in those landing pads.
> rustc maybe cleaning up the objects that have no meaning for the verifier.
> Maybe freeing memory (but since it's arena) we don't care,
> but we will still call all the drop()s because that's what rust as a language
> promised to users and we cannot break that promise.
> kernel's rust with panic=abort needs to be fixed.
> That's orthogonal problem and definitely not something to follow.

As Kartikeya says in a sibling email, I mean generic verifier
capability to accept any program by introducing runtime checks.
Verifier's capacity to infer safety conditions for various
instructions is orthogonal to rustc's assumptions about landing pad
boundaries. E.g. rustc/llvm might infer that certain memory access is
within bounds and optimize bound checks out, it is not a given that
verifier would come to a same conclusion and that some landing pad
would be declared for an instruction.

  parent reply	other threads:[~2026-09-22  4:27 UTC|newest]

Thread overview: 80+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 21:00 [PATCH bpf-next v4 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 01/20] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:27     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 02/20] bpf: Add the bpf_unwind_resume() kfunc Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:31     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 03/20] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-22  4:04   ` Alexei Starovoitov
2026-09-22  5:28     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 04/20] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-22 18:27   ` Eduard Zingerman
2026-09-23  3:07     ` Yonghong Song
2026-09-23  3:54       ` Eduard Zingerman
2026-09-23  4:05         ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 05/20] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 06/20] bpf: Explore the landing pads no call site reaches Yonghong Song
2026-09-21 23:58   ` Eduard Zingerman
2026-09-22  3:32     ` Yonghong Song
2026-09-22  4:10       ` Eduard Zingerman
2026-09-21 21:01 ` [PATCH bpf-next v4 07/20] bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch Yonghong Song
2026-09-21 21:20   ` sashiko-bot
2026-09-22  3:39     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:44     ` Yonghong Song
2026-09-22  0:30   ` Eduard Zingerman
2026-09-22  3:45     ` Yonghong Song
2026-09-22 21:43       ` Eduard Zingerman
2026-09-23  3:11         ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 08/20] bpf: Walk the exception unwind in the verifier Yonghong Song
2026-09-21 21:40   ` sashiko-bot
2026-09-22  4:17     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  5:21     ` Yonghong Song
2026-09-22  4:08   ` Alexei Starovoitov
2026-09-22  5:25     ` Yonghong Song
2026-09-22 21:53       ` Eduard Zingerman
2026-09-23  3:18         ` Yonghong Song
2026-09-22 23:43   ` Eduard Zingerman
2026-09-23  3:21     ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 09/20] bpf: Refuse a private stack for a program with an exception cleanup table Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 10/20] bpf: Dispatch exception cleanup pads from bpf_throw() Yonghong Song
2026-09-22 21:38   ` Eduard Zingerman
2026-09-23  3:22     ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 11/20] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 12/20] bpf, arm64: " Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 13/20] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-21 21:13   ` sashiko-bot
2026-09-21 21:01 ` [PATCH bpf-next v4 14/20] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 15/20] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-21 21:20   ` sashiko-bot
2026-09-21 21:01 ` [PATCH bpf-next v4 16/20] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-21 21:02 ` [PATCH bpf-next v4 17/20] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-21 21:02 ` [PATCH bpf-next v4 18/20] selftests/bpf: Add an end-to-end .bpf_cleanup exception test Yonghong Song
2026-09-21 21:22   ` sashiko-bot
2026-09-22  5:26     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-21 21:02 ` [PATCH bpf-next v4 19/20] selftests/bpf: Cover the exception cleanup shapes the chain does not reach Yonghong Song
2026-09-21 21:19   ` sashiko-bot
2026-09-21 21:02 ` [PATCH bpf-next v4 20/20] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
2026-09-22  1:08 ` [PATCH bpf-next v4 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Eduard Zingerman
2026-09-22  2:16   ` Alexei Starovoitov
2026-09-22  2:31     ` Kumar Kartikeya Dwivedi
2026-09-22 21:44       ` Alexei Starovoitov
2026-09-23  4:36         ` Kumar Kartikeya Dwivedi
2026-09-23  4:54           ` Alexei Starovoitov
2026-09-23  5:20             ` Kumar Kartikeya Dwivedi
2026-09-23  6:16             ` Eduard Zingerman
2026-09-23  6:44               ` Kumar Kartikeya Dwivedi
2026-09-22  4:27     ` Eduard Zingerman [this message]
2026-09-22 21:47       ` Alexei Starovoitov
2026-09-22 23:08         ` Eduard Zingerman
2026-09-22 23:37           ` Alexei Starovoitov
2026-09-23  0:04             ` Eduard Zingerman
2026-09-23 19:04               ` Eduard Zingerman
2026-09-23 19:24                 ` Andrii Nakryiko
2026-09-23 19:34                   ` Kumar Kartikeya Dwivedi
2026-09-23 21:34                     ` Alexei Starovoitov
2026-09-23 22:00                       ` Eduard Zingerman
2026-09-23 23:22                         ` Alexei Starovoitov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7eba4eb055e15d5c78f463d013fa98bb21d7b494.camel@gmail.com \
    --to=eddyz87@gmail.com \
    --cc=alexei.starovoitov@gmail.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=kernel-team@fb.com \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox