BPF List
 help / color / mirror / Atom feed
From: Yonghong Song <yonghong.song@linux.dev>
To: bot+bpf-ci@kernel.org, bpf@vger.kernel.org
Cc: ast@kernel.org, andrii@kernel.org, daniel@iogearbox.net,
	eddyz87@gmail.com, kernel-team@fb.com, martin.lau@kernel.org,
	mason@kernel.org, ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next v7 19/22] selftests/bpf: Add end-to-end and negative .bpf_cleanup exception tests
Date: Tue, 29 Sep 2026 18:42:45 -0700	[thread overview]
Message-ID: <e0a5e59a-23f9-4a5d-bb83-07e2f6948594@linux.dev> (raw)
In-Reply-To: <6a088778cba5c689e9024c435e0e092047176fff11c56ce6cb04d732b6073c34@mail.kernel.org>



On 9/28/26 5:52 PM, bot+bpf-ci@kernel.org wrote:
>> diff --git a/tools/testing/selftests/bpf/progs/exceptions_cleanup_fail.c b/tools/testing/selftests/bpf/progs/exceptions_cleanup_fail.c
>> new file mode 100644
>> index 000000000000..76cca8dc45a9
>> --- /dev/null
>> +++ b/tools/testing/selftests/bpf/progs/exceptions_cleanup_fail.c
>> @@ -0,0 +1,878 @@
> [ ... ]
>
>> +static __used __noinline void __kfunc_btf_anchor(void)
>> +{
>> +	bpf_throw(0);
>> +	bpf_unwind();
>> +	bpf_preempt_disable();
>> +	bpf_preempt_enable();
>> +	bpf_rcu_read_lock();
>> +	bpf_rcu_read_unlock();
>> +	bpf_unwind_resume(NULL);
>> +}
>> +
>> +/* An unwind raised in a callee, which is how a cleanup region gets one. */
>> +static __used __naked __noinline __u64 inner_unwind(void)
>> +{
>> +	asm volatile (
>> +	"r1 = 1;"
>> +	"call bpf_unwind;"
>> +	"r0 = 0;"
>> +	"exit;"
>> +	::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 unwind_in_pad_frame(void)
>> +{
>> +	asm volatile (
>> +	"call bpf_preempt_disable;"
>> +"1:"	"call inner_unwind;"		/* cleanup region */
>> +"2:"
>> +	"call bpf_preempt_enable;"
>> +	"r0 = 0;"
>> +	"exit;"
>> +"3:"					/* landing pad that unwinds again */
>> +	"call bpf_preempt_enable;"
>> +	"r1 = 2;"
>> +	"call bpf_unwind;"
>> +	"call bpf_unwind_resume;"
>> +	"exit;"
>> +	CLEANUP_REC("1b", "2b", "3b")
>> +	::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 cb_and_table_frame(void)
>> +{
>> +	asm volatile (
>> +	"call bpf_preempt_disable;"
>> +	"r1 = 9;"
>> +"1:"	"call bpf_unwind;"		/* cleanup region */
>> +"2:"
>> +	"r0 = 0;"
>> +	"exit;"
>> +"3:"					/* landing pad */
>> +	"call bpf_preempt_enable;"
>> +	"call bpf_unwind_resume;"
>> +	"exit;"
>> +	CLEANUP_REC("1b", "2b", "3b")
>> +	::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 pad_calls_thrower_frame(void)
>> +{
>> +	asm volatile (
>> +	"call bpf_preempt_disable;"
>> +	"r1 = 11;"
>> +"1:"	"call bpf_unwind;"		/* cleanup region */
>> +"2:"
>> +	"r0 = 0;"
>> +	"exit;"
>> +"3:"					/* landing pad */
>> +	"call pad_callee_that_throws;"	/* ...which can throw: refused */
>> +	"call bpf_preempt_enable;"
>> +	"call bpf_unwind_resume;"
>> +	"exit;"
>> +	CLEANUP_REC("1b", "2b", "3b")
>> +	::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 catch_pad_frame(void)
>> +{
>> +	asm volatile (
>> +	"call bpf_preempt_disable;"
>> +	"r1 = 12;"
>> +"1:"	"call bpf_unwind;"		/* cleanup region */
>> +"2:"
>> +	"r0 = 0;"
>> +	"exit;"
>> +"3:"					/* catch pad: no resume, it stops here */
>> +	"call bpf_preempt_enable;"
>> +	"r0 = 0;"
>> +	"exit;"
>> +	CLEANUP_REC("1b", "2b", "3b")
>> +	::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 stray_resume_frame(void)
>> +{
>> +	asm volatile (
>> +	"call bpf_preempt_disable;"
>> +	"r1 = 13;"
>> +"1:"	"call bpf_unwind;"		/* cleanup region */
>> +"2:"
>> +	"r0 = 0;"
>> +	"exit;"
>> +"3:"					/* landing pad */
>> +	"call bpf_preempt_enable;"
>> +	"call bpf_unwind_resume;"
>> +	"exit;"
>> +	CLEANUP_REC("1b", "2b", "3b")
>> +	::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline __u64 pad_calls_resumer_frame(void)
>> +{
>> +	asm volatile (
>> +	"call bpf_preempt_disable;"
>> +	"r1 = 14;"
>> +"1:"	"call bpf_unwind;"		/* cleanup region */
>> +"2:"
>> +	"r0 = 0;"
>> +	"exit;"
>> +"3:"					/* landing pad */
>> +	"call bpf_preempt_enable;"
>> +	"call resume_in_callee;"	/* ...which resumes: refused */
>> +	"call bpf_unwind_resume;"
>> +	"exit;"
>> +	CLEANUP_REC("1b", "2b", "3b")
>> +	::: __clobber_all);
>> +}
> [ ... ]
>
>> +static __used __naked __noinline void gotox_unwinder(void)
>> +{
>> +	asm volatile (
>> +	"r1 = 15;"
>> +	"call bpf_unwind;"
>> +	"exit;"
>> +	::: __clobber_all);
>> +}
> This isn't a bug, but bpf_unwind() is declared as __bpf_kfunc void
> bpf_unwind(void) in kernel/bpf/helpers.c and takes no arguments.
>
> Several of these inline asm frames load r1 with a numbered value right
> before calling bpf_unwind: r1=1 in inner_unwind, r1=2 in
> unwind_in_pad_frame, r1=9 in cb_and_table_frame, r1=11 in
> pad_calls_thrower_frame, r1=12 in catch_pad_frame, r1=13 in
> stray_resume_frame, r1=14 in pad_calls_resumer_frame, and r1=15 in
> gotox_unwinder.
>
> Other bpf_unwind call sites in the same file like pad_drops_caller_lock_frame,
> no_pad_keeps_own_lock_frame, and pad_drops_caller_ref_frame call bpf_unwind
> without setting r1 first. The verifier checks no arguments for a zero-argument
> kfunc, and neither bpf_exc_keep_exits nor the runtime walk uses r1.
>
> Are the "r1 = N;" loads before these calls left over from an earlier
> cookie-style signature? Could they be dropped so the asm matches the kfunc
> prototype?

Will fix. thanks!

>
>
> ---
> AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
> See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
>
> CI run summary: https://github.com/kernel-patches/bpf/actions/runs/36502848904


  reply	other threads:[~2026-09-30  1:42 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  0:16 [PATCH bpf-next v7 00/22] bpf: Run exception cleanup landing pads when bpf_unwind() unwinds Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 01/22] bpf: Pack bpf_insn_aux_data flags into bit fields Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 02/22] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 03/22] bpf: Add the bpf_unwind() and bpf_unwind_resume() kfuncs Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 04/22] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-29  0:33   ` sashiko-bot
2026-09-29 21:58     ` Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 05/22] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-29  0:31   ` sashiko-bot
2026-09-29 22:04     ` Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 06/22] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 07/22] bpf: Resume a covered call at its landing pad Yonghong Song
2026-09-29  0:31   ` sashiko-bot
2026-09-30  0:28     ` Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 08/22] bpf: Require an unwind to leave a frame holding what it entered with Yonghong Song
2026-09-29  0:36   ` sashiko-bot
2026-09-30  1:09     ` Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  1:10     ` Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 09/22] bpf: Refuse a landing pad that does not resume Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 10/22] bpf: Refuse a private stack for a program that can unwind Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 11/22] bpf: Dispatch cleanup pads by rewriting return addresses Yonghong Song
2026-09-29  1:14   ` bot+bpf-ci
2026-09-30  1:18     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 12/22] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-29  0:30   ` sashiko-bot
2026-09-30  1:34     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 13/22] bpf, arm64: " Yonghong Song
2026-09-29  1:14   ` bot+bpf-ci
2026-09-29  0:17 ` [PATCH bpf-next v7 14/22] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 15/22] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 16/22] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 17/22] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 18/22] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 19/22] selftests/bpf: Add end-to-end and negative .bpf_cleanup exception tests Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  1:42     ` Yonghong Song [this message]
2026-09-29  0:17 ` [PATCH bpf-next v7 20/22] selftests/bpf: Add __set_global() and __ret_global() test tags Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  1:46     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 21/22] selftests/bpf: Cover more accepted .bpf_cleanup exception shapes Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  2:19     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 22/22] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  3:12     ` Yonghong Song

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e0a5e59a-23f9-4a5d-bb83-07e2f6948594@linux.dev \
    --to=yonghong.song@linux.dev \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bot+bpf-ci@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=ihor.solodrai@linux.dev \
    --cc=kernel-team@fb.com \
    --cc=martin.lau@kernel.org \
    --cc=mason@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox