From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm2-f10.google.com (mail-wm2-f10.google.com [74.125.225.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B88BE41DEF8 for ; Mon, 20 Jul 2026 14:24:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.138 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784557489; cv=none; b=JlCZbOl4RPZOvd7lKTejnjktV2q/tkbXOerMlI+HpK6t2Zz/GHwim9ts2Qy7RHbtz2AZvxc+Njd5fizlD/TpgTulpNKsSQ5pELi1olhoYiwmWxrvlLHJdg9PTzInG+USrgM028Bj8j+iJiAHWiK9jc7DLCJ9Z1aY+jkiBxw6I24= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784557489; c=relaxed/simple; bh=WY4da/eZLxxQmiBbPjg8+Of4x2fEz1afwkY5i+KDZGo=; h=Mime-Version:Content-Type:Date:Message-Id:Cc:Subject:From:To: References:In-Reply-To; b=aUQem5W7g/lR2zdlyUTmY01rqze3sevvBxSen//HWU6hyY67DTy5XwzlE9cErvDpGq7FAyDXJL1x9U2v2UT+FPQiq3hbVfOeqxaOI7QFrfFxpWlyABfkdsrg7urz11ALutUOx2kBWu6APCclvBXluy03e6xmcnbndPrMbCj+Jww= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=BPThb9AI; arc=none smtp.client-ip=74.125.225.138 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="BPThb9AI" Received: by mail-wm2-f10.google.com with SMTP id 5b1f17b1804b1-495501e57beso6703185e9.1 for ; Mon, 20 Jul 2026 07:24:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784557486; x=1785162286; darn=vger.kernel.org; h=in-reply-to:references:to:from:subject:cc:message-id:date :content-type:content-transfer-encoding:mime-version:from:to:cc :subject:date:message-id:reply-to:content-type; bh=WY4da/eZLxxQmiBbPjg8+Of4x2fEz1afwkY5i+KDZGo=; b=BPThb9AIb0DY1uqtP98pAceUa726XNT6s7fy0bOABefqTOrhBj+YsSJCbFMxnK0Ra0 dQ0tYrrpQWjADBL2IJki1Fbv53823/lOAl2xJu0l1WSdGW1fJQ2f3Nht7OciivXF1pIE nQxSyFyQcwm6MoGXCNff2X/x7iGZUzQCOBI1w0GR81ViTKKMc38XVnTm52HnGptiFZuZ FAmYf8xcQhsFgpxXF+laX1stcPYLT2syKUTEbnV3OXITxdJpakYsC/0d+7XsOklBsIME ys9Y9QHGicu6ZEhneBwJKrMY+VUVkGjQohOF10y2hvHMP+Glnjo349Cf2c5LOjEMqTQp uzzg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784557486; x=1785162286; h=in-reply-to:references:to:from:subject:cc:message-id:date :content-type:content-transfer-encoding:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=WY4da/eZLxxQmiBbPjg8+Of4x2fEz1afwkY5i+KDZGo=; b=NIYoF9t9UqPn1S8TyJO3+LyH4fAgh6rnz9fR6XzamG7k49SCShvDo9fsaChwsg65B0 SzHWFOPOyIAFGr1jUNit5qqOfNc7G6RLNYsKjGwodBXXQY8NpEq5Ksp6keNw9yhuq8NJ ZFVVUU6NAitJk9Gc93zc6SAam8WntIYmxQJU3xdyCyGUg/zcy3RZr8GDbaTlIrmovu5P wDHW4EmrWdS45aBFI9JWKjF2cE/qfEb0lEz/zLOuwmPynQ1fxHBOcGGBqs5L5BWUWTzS G12Wa4nvfCUnhmVVZj1ZFAOmsEf0nEZBOnslfUkrGJzB7Qg6Xuw+nzk/hSlnzEPRHiU0 8yow== X-Forwarded-Encrypted: i=1; AHgh+RqUr/Gp+ms8hwODRlpTbn8RA2M/W4x8gQ9tRTkqiBUIrc015WWbtQn7TboT/5Rc52/umCviF8FHzw4T+X4=@vger.kernel.org X-Gm-Message-State: AOJu0Ywi2wsd/ZwUdTY4dH3e4foIrhbuVumsuFq6ekIoL/xl5lS2Fbyj ISkvD005qJzwsN+IqdrXlCHuzaEzGSQGnWa9vP+rwyOiSjR9oO1/Zmoj X-Gm-Gg: AfdE7clc9Ns9dT9+OQcCm8nYkLSu4BmROjLZtiv43M2uWx7sLl9SgNA2H3Ohm2La5C7 rP8yhs+QQWnPGJy117YVrplDh5dbV+lBjFkNKm9rLnMGSZ2fcl45qqyKbB8wF6Ym9bS+I1u/AeQ pHIa3Njp/9mu7JwAx5IH3S1TeMLJm1N0bI6KdrrUUzw0bZBBNmPZQbSvkyJ9VtSXawY9f6/Q+XM Y6N9RkBnDu8tODlTZajJTyW34p5Csfp3GODym9hLzH72IiBj0eqB/zp45z6xOpbaMTPT14/xR5c CBVRvzYEQIWODTyiiJE+f0DEhMI4Eu8xaBqD7qh3QXkhc50LHyLK/Cc82IQJuhEeqcFv5Pl6s9n VzGrxgWTalkHY+WPOxAFanNmfCk41sm8dbkIxwOWLkjoTSXHWqkkRPuLvWljNubrScgDNvxYFNg wwxPhg3BxihZnVXSx3hcFAYx6u05bLUtFTQy6p4R+k4aw2H/HK1LIFB1I1dUqF+EnGuVyjeAOda eU6VzCnhmo/HT3bVL9SqJB0r3CdfGAutRNNxeqKN2HKi2YeaCSgid8= X-Received: by 2002:a05:600c:ad7:b0:495:3c6d:f294 with SMTP id 5b1f17b1804b1-4954a402da3mr118155185e9.23.1784557485673; Mon, 20 Jul 2026 07:24:45 -0700 (PDT) Received: from localhost (nat-icclus-192-26-29-3.epfl.ch. [192.26.29.3]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f67466e09sm32026063f8f.21.2026.07.20.07.24.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 07:24:44 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Mon, 20 Jul 2026 16:24:44 +0200 Message-Id: Cc: "Daniel Borkmann" , , , , , , , , , , , , , , , , , , , , , , , Subject: Re: [PATCH bpf-next v6 6/7] riscv, bpf: Mixing bpf2bpf and tailcalls From: "Kumar Kartikeya Dwivedi" To: "Pu Lehui" , =?utf-8?q?Bj=C3=B6rn_T=C3=B6pel?= X-Mailer: aerc 0.21.0 References: <20260708064436.2971933-7-pulehui@huaweicloud.com> <23cb9eac-1775-44b8-a9ec-10edde808a30@huaweicloud.com> <326eda4a-39e6-4f1e-8fe5-dc1cc9ae6739@iogearbox.net> In-Reply-To: On Fri Jul 17, 2026 at 9:37 AM CEST, Pu Lehui wrote: > > > On 2026/7/10 17:43, Daniel Borkmann wrote: >> On 7/10/26 2:53 AM, Pu Lehui wrote: >>> On 2026/7/10 3:51, Bj=C3=B6rn T=C3=B6pel wrote: >>>> On Thu, 9 Jul 2026 at 17:09, Pu Lehui wrote: >>>>> On 2026/7/9 19:37, Bj=C3=B6rn T=C3=B6pel wrote: >>>>>> Sorry for the delay here -- the bot had me thinking a bit. >>>>>> >>>>>> On Wed, 8 Jul 2026 at 10:54, Pu Lehui wrot= e: >>>>>> ... >>>>>> >>>>>>>> This assumes a fixed number of instructions before the tailcall >>>>>>>> entry >>>>>>>> point. When is_subprog is true, the rv_addi() instruction is not >>>>>>>> emitted, >>>>>>>> which means the tailcall entry point moves forward by 4 bytes >>>>>>>> relative to >>>>>>>> where RV_TAILCALL_OFFSET expects it to be. >>>>>>>> >>>>>>>> The tailcall entry is used in emit_bpf_tail_call() when >>>>>>>> calculating the >>>>>>>> jump target for the tail call. If RV_TAILCALL_OFFSET doesn't >>>>>>>> account for >>>>>>>> the conditional emission, could this cause the wrong entry point >>>>>>>> to be >>>>>>>> used when tail calling into subprograms? >>>>>>> >>>>>>> This is not an issue, subprog can not be the tailcall callee. >>>>>> >>>>>> Say, that we have an entry function that does bpf_for_each_map_array= () >>>>>> into a callback cb(). cb() is a subprogram, so no init of TCC. Now, >>>>>> cb() calls another subprogram that does a tailcall. >>>>>> >>>>>> The callback to cb() is coming from the kernel, so a6 could have bee= n >>>>>> clobbered, no? We're entering a subprogram coming from the C ABI. No= w, >>>>>> if the callback calls a subprog that's tail-call reachable, the TCC >>>>>> can be garbage? >>>>> >>>>> Sashiko reported the same issue yesterday. I verified that the verifi= er >>>>> rejects cases where a tail call is invoked within a callback; >>>>> specifically, while the callback's return value range is [0, 1], the >>>>> simulation of the exit path in `check_helper_call` (handling the tail >>>>> call helper) marks R0 as UNKNOWN, causing the verifier to reject >>>>> it=E2=80=94so I >>>>> didn't investigate further. However, I just verified that the verifie= r >>>>> *does* accept the scenario where a callback calls a subprogram, and >>>>> that >>>>> subprogram subsequently calls a tail call. I believe this scenario >>>>> ought >>>>> to be rejected; perhaps some changes are needed in the verifier, >>>>> otherwise tail calls on other architectures (like x86) would also be >>>>> susceptible to infinite loop issues. >>>> >>>> Thanks for trying it out! >>>> >>>> Ok, so seems like we need a verifier fix pre-landing? > > Hi Bj=C3=B6rn, > > Just a quick note that the verifier fix we discussed has now landed in > bpf-next [0]. Looking forward to your feedback on v6 whenever you get a > chance. :) Yep, if there are no more concerns, it would make sense to pull this in. Bj=C3=B6rn, what do you think? > [...]