BPF List
 help / color / mirror / Atom feed
From: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
To: "Eduard Zingerman" <eddyz87@gmail.com>,
	"Yonghong Song" <yonghong.song@linux.dev>, <bpf@vger.kernel.org>
Cc: "Alexei Starovoitov" <ast@kernel.org>,
	"Andrii Nakryiko" <andrii@kernel.org>,
	"Daniel Borkmann" <daniel@iogearbox.net>, <kernel-team@fb.com>
Subject: Re: [PATCH bpf-next v5 07/21] bpf: Explore the landing pads no call site reaches
Date: Wed, 23 Sep 2026 21:28:58 +0000	[thread overview]
Message-ID: <DLN0K7231LF2.1UNIBGA546C90@gmail.com> (raw)
In-Reply-To: <df24934c5ecbd70bc35b528b8e58ae668ce02051.camel@gmail.com>

On Wed Sep 23, 2026 at 4:26 PM UTC, Eduard Zingerman wrote:
> On Tue, 2026-09-22 at 21:59 -0700, Yonghong Song wrote:
>> A cleanup record need not cover a call an exception can unwind out of: a
>> frontend is free to emit a region around a helper or an ordinary kfunc,
>> both nounwind here. Nothing marks a call site then, and that record's
>> landing pad is reached by nothing at all -- leaving bpf_check_cfg() to
>> refuse the program over code its own frontend had no way not to emit:
>> 
>>    0: call bpf_preempt_disable
>>    1: call bpf_preempt_enable      record = { begin = 1, end = 2, pad = 4 }
>>    2: r0 = 0
>>    3: exit
>>    4: r1 = pads_ran ll             landing pad
>>    6: r2 = *(u64 *)(r1 + 0)
>>    7: r2 |= RAN_NOUNWIND_REC
>>    8: *(u64 *)(r1 + 0) = r2
>>    9: call bpf_unwind_resume
>>   10: exit
>> 
>> The range [1,2) holds one call, and it is a kfunc, so an exception cannot
>> come out of it. mark_call_sites() marks nothing, nothing pushes an edge to
>> 4, and 4 through 10 are reachable from nothing: "unreachable insn 4". The
>> pad is dead, which is correct -- no exception can ever arrive at it -- but
>> the program is fine and has to load.
>> 
>> Walk every pad the table names that the edges did not reach, the way the
>> walk is already re-seeded at an exception callback. From there the pad is
>> code like any other: do_check() never enters it, because no call site
>> dispatches to it, so the dead code sweep removes it along with everything
>> else that was not reached.
>> 
>> Signed-off-by: Yonghong Song <yonghong.song@linux.dev>
>> ---
>
> Yonghong, in v4 you said that rustc does not generate dead landing pads.
> Why do we need this patch?

It's not dead. commit log is incorrect.

I bet C code that caused such asm didn't mark bpf_preempt_enable as nothrow,
so compiler correctly emitted exception table.
Now commit log argues that this helper doesn't throw in reality.
Well, too late, the mistake was made earlier.

I don't like the unwind approach taken by later patches in the series.

imo the following is cleaner:
- do not repurpose bpf_throw() for this new thing.
  Introduce new kfunc that will do the unwind, let's name it bpf_unwind() ?
- replace all 'call bpf_unwind_resume' with NOP by the verifier (or may with bpf_exit. tbd)
  Technically rustc or llvm can do that too, but it's cleaner to do in the verifier.
- In bpf_unwind() walk all exception tables and replace return addresses
  in corresponding frames to landing_pad_ip-s.
- just return from bpf_unwind().
  restoring callee saved registers will happen automatically by corresponding
  frames and there is no need to search exception tables at each step.
  That's what typical eh unwinder does, but it's doing it due to C++ logic
  that is more complex that Rust. For Rust unwinds we don't need all that.
  The above algorithm will do.

Also please add an example where [ip_start, ip_end] range is more than just a call
insn. I mentioned it couple times as the reason why 'invoke' aka 16-byte insn
approach doesn't work.
I'm pretty sure I saw such IP ranges generated by rustc.


  parent reply	other threads:[~2026-09-23 21:29 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23  4:58 [PATCH bpf-next v5 00/21] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Yonghong Song
2026-09-23  4:58 ` [PATCH bpf-next v5 01/21] bpf: Pack bpf_insn_aux_data flags into bit fields Yonghong Song
2026-09-23  5:40   ` bot+bpf-ci
2026-09-23 19:16   ` Eduard Zingerman
2026-09-23  4:58 ` [PATCH bpf-next v5 02/21] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 03/21] bpf: Add the bpf_unwind_resume() kfunc Yonghong Song
2026-09-23  6:13   ` Kumar Kartikeya Dwivedi
2026-09-23  4:59 ` [PATCH bpf-next v5 04/21] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 05/21] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-23  5:40   ` bot+bpf-ci
2026-09-23  4:59 ` [PATCH bpf-next v5 06/21] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-23  5:51   ` bot+bpf-ci
2026-09-23 19:25   ` Eduard Zingerman
2026-09-23  4:59 ` [PATCH bpf-next v5 07/21] bpf: Explore the landing pads no call site reaches Yonghong Song
2026-09-23 16:26   ` Eduard Zingerman
2026-09-23 17:27     ` Yonghong Song
2026-09-23 18:06       ` Eduard Zingerman
2026-09-23 18:09         ` Yonghong Song
2026-09-23 21:28     ` Alexei Starovoitov [this message]
2026-09-23 22:19       ` Eduard Zingerman
2026-09-23 23:20         ` Alexei Starovoitov
2026-09-24  0:13           ` Kumar Kartikeya Dwivedi
2026-09-24  1:53             ` Alexei Starovoitov
2026-09-24  6:12               ` Kumar Kartikeya Dwivedi
2026-09-23 23:09       ` Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 08/21] bpf: Walk the exception unwind in the verifier Yonghong Song
2026-09-23 16:34   ` Eduard Zingerman
2026-09-23 18:01     ` Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 09/21] bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 10/21] bpf: Refuse a private stack for a program with an exception cleanup table Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 11/21] bpf: Dispatch exception cleanup pads from bpf_throw() Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 12/21] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-23  6:45   ` Eduard Zingerman
2026-09-23 20:45     ` Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 13/21] bpf, arm64: " Yonghong Song
2026-09-23  4:59 ` [PATCH bpf-next v5 14/21] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-23  8:36   ` Kumar Kartikeya Dwivedi
2026-09-23  5:00 ` [PATCH bpf-next v5 15/21] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-23  5:00 ` [PATCH bpf-next v5 16/21] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-23  5:52   ` Kumar Kartikeya Dwivedi
2026-09-23  5:00 ` [PATCH bpf-next v5 17/21] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-23  5:00 ` [PATCH bpf-next v5 18/21] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-23  5:40   ` bot+bpf-ci
2026-09-23  5:00 ` [PATCH bpf-next v5 19/21] selftests/bpf: Add an end-to-end .bpf_cleanup exception test Yonghong Song
2026-09-23  5:51   ` bot+bpf-ci
2026-09-23  5:00 ` [PATCH bpf-next v5 20/21] selftests/bpf: Cover the exception cleanup shapes the chain does not reach Yonghong Song
2026-09-23  5:51   ` bot+bpf-ci
2026-09-23  7:50   ` Eduard Zingerman
2026-09-23  5:00 ` [PATCH bpf-next v5 21/21] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DLN0K7231LF2.1UNIBGA546C90@gmail.com \
    --to=alexei.starovoitov@gmail.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=kernel-team@fb.com \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox