From: Eduard Zingerman <eddyz87@gmail.com>
To: Alexei Starovoitov <alexei.starovoitov@gmail.com>, bpf@vger.kernel.org
Cc: daniel@iogearbox.net, andrii@kernel.org, memxor@gmail.com
Subject: Re: [PATCH bpf-next v2 04/17] bpf: Prepare static analysis passes for callx instruction
Date: Wed, 23 Sep 2026 21:18:44 -0700 [thread overview]
Message-ID: <8b89e604c8b774ee0597239f113c308dcb256420.camel@gmail.com> (raw)
In-Reply-To: <20260924031042.1690890-5-alexei.starovoitov@gmail.com>
On Thu, 2026-09-24 at 03:10 +0000, Alexei Starovoitov wrote:
> From: Alexei Starovoitov <ast@kernel.org>
>
> BPF_JMP | BPF_CALL | BPF_X (callx) will be an indirect call of static
> subprog with address in dst_reg. The passes that run before the main
> verifier pass don't know which subprog callx calls.
> Teach them to treat callx as a call with unknown callee:
>
> - const_fold: callx clobbers R0-R5 like any other call. Otherwise
> bpf_prune_dead_branches() could rewrite a live conditional jump.
>
> - live regs: callx uses R1-R5 and dst_reg, defines R0-R5.
>
> - stack liveness: func instances are keyed by (callsite, depth) and
> cannot describe a callsite with multiple callees. Don't create
> instances for callees of callx. If any callx argument is derived
> from fp mark stack of all frames as read at callx insn and keep slots
> of outer frames alive 'before' the callsite while the callee is
> verified. Same as for callbacks that are not known statically.
> The callee is analyzed as standalone instance.
>
> - backtracking: treat callx as a call of static subprog, same as
> BPF_PSEUDO_CALL.
>
> callx is still rejected as unknown opcode. No functional change.
>
> Signed-off-by: Alexei Starovoitov <ast@kernel.org>
> ---
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
...
next prev parent reply other threads:[~2026-09-24 4:18 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 3:10 [PATCH bpf-next v2 00/17] bpf: Indirect calls of bpf subprogs (callx) Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 01/17] bpf: Fix infinite loop in check_max_stack_depth() Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 02/17] selftests/bpf: Test recursion through a global function and a callback Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 03/17] bpf: Keep functions with address taken when removing dead code Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 04/17] bpf: Prepare static analysis passes for callx instruction Alexei Starovoitov
2026-09-24 3:56 ` bot+bpf-ci
2026-09-24 4:18 ` Eduard Zingerman [this message]
2026-09-24 3:10 ` [PATCH bpf-next v2 05/17] bpf: Add callx instruction to call bpf subprogs indirectly Alexei Starovoitov
2026-09-24 3:28 ` sashiko-bot
2026-09-24 3:10 ` [PATCH bpf-next v2 06/17] bpf: Add callx calls to the call graph Alexei Starovoitov
2026-09-24 3:26 ` sashiko-bot
2026-09-24 3:56 ` bot+bpf-ci
2026-09-24 5:00 ` Eduard Zingerman
2026-09-24 3:10 ` [PATCH bpf-next v2 07/17] bpf, x86: Add JIT support for callx Alexei Starovoitov
2026-09-24 5:33 ` Eduard Zingerman
2026-09-24 3:10 ` [PATCH bpf-next v2 08/17] bpf, arm64: " Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 09/17] bpf: Discover subprogs described by func_info Alexei Starovoitov
2026-09-24 5:42 ` Eduard Zingerman
2026-09-24 3:10 ` [PATCH bpf-next v2 10/17] bpf: Recognize pointers to functions in read-only maps Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 11/17] libbpf: Support pointers to static functions in data when linking Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 12/17] libbpf: Resolve pointers to functions in read-only data Alexei Starovoitov
2026-09-24 3:27 ` sashiko-bot
2026-09-24 3:10 ` [PATCH bpf-next v2 13/17] libbpf: Treat .data.rel.ro as " Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 14/17] libbpf: Support pointers to functions in read-only data in light skeleton Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 15/17] selftests/bpf: Add tests for callx Alexei Starovoitov
2026-09-24 3:56 ` bot+bpf-ci
2026-09-24 3:10 ` [PATCH bpf-next v2 16/17] selftests/bpf: Add tests for callx through pointers in read-only data Alexei Starovoitov
2026-09-24 3:10 ` [PATCH bpf-next v2 17/17] bpf, docs: Document callx instruction Alexei Starovoitov
2026-09-24 5:50 ` [PATCH bpf-next v2 00/17] bpf: Indirect calls of bpf subprogs (callx) patchwork-bot+netdevbpf
2026-09-24 5:55 ` Eduard Zingerman
2026-09-24 6:00 ` Alexei Starovoitov
2026-09-24 17:50 ` Ihor Solodrai
2026-09-24 18:09 ` Alexei Starovoitov
2026-09-28 23:13 ` Ihor Solodrai
2026-09-29 6:04 ` Alexei Starovoitov
2026-09-29 16:40 ` Ihor Solodrai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8b89e604c8b774ee0597239f113c308dcb256420.camel@gmail.com \
--to=eddyz87@gmail.com \
--cc=alexei.starovoitov@gmail.com \
--cc=andrii@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=memxor@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox