From: Yonghong Song <yonghong.song@linux.dev>
To: bot+bpf-ci@kernel.org, bpf@vger.kernel.org
Cc: ast@kernel.org, andrii@kernel.org, daniel@iogearbox.net,
eddyz87@gmail.com, kernel-team@fb.com, martin.lau@kernel.org,
mason@kernel.org, ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next v2 09/20] bpf: Refuse a private stack for a program with an exception cleanup table
Date: Sat, 19 Sep 2026 12:37:45 -0700 [thread overview]
Message-ID: <c4c47944-578d-4694-8933-c8fbb09e76e9@linux.dev> (raw)
In-Reply-To: <6d68bdd97e85a2c8b74ab62769fd7846a3f9c83f825697eb9fd35a6723842a73@mail.kernel.org>
On 9/17/26 10:44 PM, bot+bpf-ci@kernel.org wrote:
>> A landing pad is about to start running outside its own frame, on the
>> bpf_throw() walker's stack, with that frame's registers put back from a
>> spill area whose contents arch_bpf_run_cleanup_pad() knows how to read. The
>> x86-64 JIT addresses a private-stack program's frame through a scratch
>> register that it recomputes after each call rather than through rbp, and no
>> spill area holds that register, so a pad there would address its frame
>> through whatever the kernel left behind.
> The description says the x86-64 JIT 'recomputes after each call'. Does the
> JIT actually recompute it?
>
> Looking at the x86 JIT, emit_priv_frame_ptr() (arch/x86/net/bpf_jit_comp.c)
> is emitted once in the prologue, and the value in X86_REG_R9 is carried
> across calls by push_r9()/pop_r9() around each call site; BPF_REG_FP
> accesses are rewritten to X86_REG_R9.
>
> The load-bearing half of the argument is still correct -
> arch_bpf_run_cleanup_pad() (added later in the series,
> arch/x86/net/bpf_cleanup_pad.S) restores only r15/r14/r13/rbx/r12 and rbp
> from the spill area and never restores r9, so a pad in a private-stack
> program would address its frame through a stale register.
>
> Only the described mechanism (recompute vs save/restore around calls) is
> wrong, which makes the justification harder to check against the JIT.
>
>> Everywhere rather than arch-conditionally: arm64 keeps its private
>> stack pointer in x27, which is in the prologue spill and so survives, but a
>> rule that holds on one arch and not the other is not worth the second code
>> path when nothing is lost but an optimization.
> Does 'nothing is lost but an optimization' understate the effect?
>
> The private-stack mode also changes the verifier's stack-depth accounting,
> not just JIT codegen. In check_max_stack_depth_subprog() a
> PRIV_STACK_ADAPTIVE subprog is checked against MAX_BPF_STACK on its own ('if
> (subprog_depth > MAX_BPF_STACK)'), while a NO_PRIV_STACK subprog accumulates
> into 'depth' and the whole bpf2bpf chain must fit in MAX_BPF_STACK
> ('combined stack size of %d calls is %d. Too large').
>
> So for the prog types bpf_enable_priv_stack() would have returned
> PRIV_STACK_ADAPTIVE for (kprobe/tracepoint/perf_event/raw_tp, and
> tracing/lsm/struct_ops with a recursion or an explicit request), a program
> carrying a cleanup table whose nested subprog depths sum above 512 bytes now
> fails to load rather than losing performance.
>
> Worth stating in the changelog, since it is a load-time visible restriction
> on the new feature rather than an optimization.
Okay, comments and commit message may have some stale things or something
like (when nothing is lost but an optimization) is not correct. Will fix.
>
> Related: kernel/sched/ext/ext.c sets prog->aux->priv_stack_requested for
> sched_ext dispatch/sub_caps_updated, and verifier.c rejects such a request
> when the JIT cannot honour it; here the request is silently ignored instead.
>
> This looks like a bug fix for private stack support. Should this include:
>
> Fixes: a76ab5731e32d ("bpf: Find eligible subprogs for private stack support")
Fixes tag is unnecessary.
>
>
> ---
> AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
> See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
>
> CI run summary: https://github.com/kernel-patches/bpf/actions/runs/35308528711
next prev parent reply other threads:[~2026-09-19 19:37 UTC|newest]
Thread overview: 56+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 4:41 [PATCH bpf-next v2 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 01/20] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 02/20] bpf: Add the bpf_unwind_resume() kfunc Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 03/20] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-18 5:44 ` bot+bpf-ci
2026-09-19 4:55 ` Alexei Starovoitov
2026-09-19 17:42 ` Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 04/20] bpf: Mark the call sites an exception cleanup table covers Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 05/20] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-18 4:59 ` sashiko-bot
2026-09-19 19:17 ` Yonghong Song
2026-09-18 5:44 ` bot+bpf-ci
2026-09-19 19:32 ` Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 06/20] bpf: Explore the landing pads no call site reaches Yonghong Song
2026-09-18 5:44 ` bot+bpf-ci
2026-09-19 19:32 ` Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 07/20] bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 08/20] bpf: Walk the exception unwind in the verifier Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 09/20] bpf: Refuse a private stack for a program with an exception cleanup table Yonghong Song
2026-09-18 5:44 ` bot+bpf-ci
2026-09-19 19:37 ` Yonghong Song [this message]
2026-09-18 4:42 ` [PATCH bpf-next v2 10/20] bpf: Dispatch exception cleanup pads from bpf_throw() Yonghong Song
2026-09-18 5:58 ` bot+bpf-ci
2026-09-19 19:54 ` Yonghong Song
2026-09-18 4:42 ` [PATCH bpf-next v2 11/20] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-18 5:03 ` sashiko-bot
2026-09-19 20:00 ` Yonghong Song
2026-09-18 5:44 ` bot+bpf-ci
2026-09-19 20:04 ` Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 12/20] bpf, arm64: " Yonghong Song
2026-09-18 5:44 ` bot+bpf-ci
2026-09-19 20:07 ` Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 13/20] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 14/20] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-18 4:57 ` sashiko-bot
2026-09-19 20:18 ` Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 15/20] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-18 5:00 ` sashiko-bot
2026-09-19 20:21 ` Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 16/20] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-18 5:02 ` sashiko-bot
2026-09-19 20:27 ` Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 17/20] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-18 5:01 ` sashiko-bot
2026-09-19 20:31 ` Yonghong Song
2026-09-18 5:44 ` bot+bpf-ci
2026-09-19 20:32 ` Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 18/20] selftests/bpf: Add an end-to-end .bpf_cleanup exception test Yonghong Song
2026-09-18 4:59 ` sashiko-bot
2026-09-18 5:58 ` bot+bpf-ci
2026-09-19 20:34 ` Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 19/20] selftests/bpf: Cover the exception cleanup shapes the chain does not reach Yonghong Song
2026-09-18 5:01 ` sashiko-bot
2026-09-18 5:44 ` bot+bpf-ci
2026-09-19 21:13 ` Yonghong Song
2026-09-18 4:43 ` [PATCH bpf-next v2 20/20] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c4c47944-578d-4694-8933-c8fbb09e76e9@linux.dev \
--to=yonghong.song@linux.dev \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bot+bpf-ci@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=ihor.solodrai@linux.dev \
--cc=kernel-team@fb.com \
--cc=martin.lau@kernel.org \
--cc=mason@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox