From: Yonghong Song <yonghong.song@linux.dev>
To: bot+bpf-ci@kernel.org, bpf@vger.kernel.org
Cc: ast@kernel.org, andrii@kernel.org, daniel@iogearbox.net,
eddyz87@gmail.com, kernel-team@fb.com, martin.lau@kernel.org,
mason@kernel.org, ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next v7 19/22] selftests/bpf: Add end-to-end and negative .bpf_cleanup exception tests
Date: Tue, 29 Sep 2026 18:42:45 -0700 [thread overview]
Message-ID: <e0a5e59a-23f9-4a5d-bb83-07e2f6948594@linux.dev> (raw)
In-Reply-To: <6a088778cba5c689e9024c435e0e092047176fff11c56ce6cb04d732b6073c34@mail.kernel.org>
On 9/28/26 5:52 PM, bot+bpf-ci@kernel.org wrote:
>> diff --git a/tools/testing/selftests/bpf/progs/exceptions_cleanup_fail.c b/tools/testing/selftests/bpf/progs/exceptions_cleanup_fail.c
>> new file mode 100644
>> index 000000000000..76cca8dc45a9
>> --- /dev/null
>> +++ b/tools/testing/selftests/bpf/progs/exceptions_cleanup_fail.c
>> @@ -0,0 +1,878 @@
> [ ... ]
>
>> +static __used __noinline void __kfunc_btf_anchor(void)
>> +{
>> + bpf_throw(0);
>> + bpf_unwind();
>> + bpf_preempt_disable();
>> + bpf_preempt_enable();
>> + bpf_rcu_read_lock();
>> + bpf_rcu_read_unlock();
>> + bpf_unwind_resume(NULL);
>> +}
>> +
>> +/* An unwind raised in a callee, which is how a cleanup region gets one. */
>> +static __used __naked __noinline __u64 inner_unwind(void)
>> +{
>> + asm volatile (
>> + "r1 = 1;"
>> + "call bpf_unwind;"
>> + "r0 = 0;"
>> + "exit;"
>> + ::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 unwind_in_pad_frame(void)
>> +{
>> + asm volatile (
>> + "call bpf_preempt_disable;"
>> +"1:" "call inner_unwind;" /* cleanup region */
>> +"2:"
>> + "call bpf_preempt_enable;"
>> + "r0 = 0;"
>> + "exit;"
>> +"3:" /* landing pad that unwinds again */
>> + "call bpf_preempt_enable;"
>> + "r1 = 2;"
>> + "call bpf_unwind;"
>> + "call bpf_unwind_resume;"
>> + "exit;"
>> + CLEANUP_REC("1b", "2b", "3b")
>> + ::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 cb_and_table_frame(void)
>> +{
>> + asm volatile (
>> + "call bpf_preempt_disable;"
>> + "r1 = 9;"
>> +"1:" "call bpf_unwind;" /* cleanup region */
>> +"2:"
>> + "r0 = 0;"
>> + "exit;"
>> +"3:" /* landing pad */
>> + "call bpf_preempt_enable;"
>> + "call bpf_unwind_resume;"
>> + "exit;"
>> + CLEANUP_REC("1b", "2b", "3b")
>> + ::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 pad_calls_thrower_frame(void)
>> +{
>> + asm volatile (
>> + "call bpf_preempt_disable;"
>> + "r1 = 11;"
>> +"1:" "call bpf_unwind;" /* cleanup region */
>> +"2:"
>> + "r0 = 0;"
>> + "exit;"
>> +"3:" /* landing pad */
>> + "call pad_callee_that_throws;" /* ...which can throw: refused */
>> + "call bpf_preempt_enable;"
>> + "call bpf_unwind_resume;"
>> + "exit;"
>> + CLEANUP_REC("1b", "2b", "3b")
>> + ::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 catch_pad_frame(void)
>> +{
>> + asm volatile (
>> + "call bpf_preempt_disable;"
>> + "r1 = 12;"
>> +"1:" "call bpf_unwind;" /* cleanup region */
>> +"2:"
>> + "r0 = 0;"
>> + "exit;"
>> +"3:" /* catch pad: no resume, it stops here */
>> + "call bpf_preempt_enable;"
>> + "r0 = 0;"
>> + "exit;"
>> + CLEANUP_REC("1b", "2b", "3b")
>> + ::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 stray_resume_frame(void)
>> +{
>> + asm volatile (
>> + "call bpf_preempt_disable;"
>> + "r1 = 13;"
>> +"1:" "call bpf_unwind;" /* cleanup region */
>> +"2:"
>> + "r0 = 0;"
>> + "exit;"
>> +"3:" /* landing pad */
>> + "call bpf_preempt_enable;"
>> + "call bpf_unwind_resume;"
>> + "exit;"
>> + CLEANUP_REC("1b", "2b", "3b")
>> + ::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 pad_calls_resumer_frame(void)
>> +{
>> + asm volatile (
>> + "call bpf_preempt_disable;"
>> + "r1 = 14;"
>> +"1:" "call bpf_unwind;" /* cleanup region */
>> +"2:"
>> + "r0 = 0;"
>> + "exit;"
>> +"3:" /* landing pad */
>> + "call bpf_preempt_enable;"
>> + "call resume_in_callee;" /* ...which resumes: refused */
>> + "call bpf_unwind_resume;"
>> + "exit;"
>> + CLEANUP_REC("1b", "2b", "3b")
>> + ::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline void gotox_unwinder(void)
>> +{
>> + asm volatile (
>> + "r1 = 15;"
>> + "call bpf_unwind;"
>> + "exit;"
>> + ::: __clobber_all);
>> +}
> This isn't a bug, but bpf_unwind() is declared as __bpf_kfunc void
> bpf_unwind(void) in kernel/bpf/helpers.c and takes no arguments.
>
> Several of these inline asm frames load r1 with a numbered value right
> before calling bpf_unwind: r1=1 in inner_unwind, r1=2 in
> unwind_in_pad_frame, r1=9 in cb_and_table_frame, r1=11 in
> pad_calls_thrower_frame, r1=12 in catch_pad_frame, r1=13 in
> stray_resume_frame, r1=14 in pad_calls_resumer_frame, and r1=15 in
> gotox_unwinder.
>
> Other bpf_unwind call sites in the same file like pad_drops_caller_lock_frame,
> no_pad_keeps_own_lock_frame, and pad_drops_caller_ref_frame call bpf_unwind
> without setting r1 first. The verifier checks no arguments for a zero-argument
> kfunc, and neither bpf_exc_keep_exits nor the runtime walk uses r1.
>
> Are the "r1 = N;" loads before these calls left over from an earlier
> cookie-style signature? Could they be dropped so the asm matches the kfunc
> prototype?
Will fix. thanks!
>
>
> ---
> AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
> See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
>
> CI run summary: https://github.com/kernel-patches/bpf/actions/runs/36502848904
next prev parent reply other threads:[~2026-09-30 1:42 UTC|newest]
Thread overview: 46+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 0:16 [PATCH bpf-next v7 00/22] bpf: Run exception cleanup landing pads when bpf_unwind() unwinds Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 01/22] bpf: Pack bpf_insn_aux_data flags into bit fields Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 02/22] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 03/22] bpf: Add the bpf_unwind() and bpf_unwind_resume() kfuncs Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 04/22] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-29 0:33 ` sashiko-bot
2026-09-29 21:58 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 05/22] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-29 0:31 ` sashiko-bot
2026-09-29 22:04 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 06/22] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 07/22] bpf: Resume a covered call at its landing pad Yonghong Song
2026-09-29 0:31 ` sashiko-bot
2026-09-30 0:28 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 08/22] bpf: Require an unwind to leave a frame holding what it entered with Yonghong Song
2026-09-29 0:36 ` sashiko-bot
2026-09-30 1:09 ` Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 1:10 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 09/22] bpf: Refuse a landing pad that does not resume Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 10/22] bpf: Refuse a private stack for a program that can unwind Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 11/22] bpf: Dispatch cleanup pads by rewriting return addresses Yonghong Song
2026-09-29 1:14 ` bot+bpf-ci
2026-09-30 1:18 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 12/22] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-29 0:30 ` sashiko-bot
2026-09-30 1:34 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 13/22] bpf, arm64: " Yonghong Song
2026-09-29 1:14 ` bot+bpf-ci
2026-09-29 0:17 ` [PATCH bpf-next v7 14/22] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 15/22] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 16/22] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 17/22] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 18/22] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 19/22] selftests/bpf: Add end-to-end and negative .bpf_cleanup exception tests Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 1:42 ` Yonghong Song [this message]
2026-09-29 0:17 ` [PATCH bpf-next v7 20/22] selftests/bpf: Add __set_global() and __ret_global() test tags Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 1:46 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 21/22] selftests/bpf: Cover more accepted .bpf_cleanup exception shapes Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 2:19 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 22/22] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 3:12 ` Yonghong Song
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e0a5e59a-23f9-4a5d-bb83-07e2f6948594@linux.dev \
--to=yonghong.song@linux.dev \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bot+bpf-ci@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=ihor.solodrai@linux.dev \
--cc=kernel-team@fb.com \
--cc=martin.lau@kernel.org \
--cc=mason@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox