[PATCH bpf v2 1/2] bpf, arm64: set up the frame pointer for the exception callback

Xu Kuohai xukuohai at huaweicloud.com
Mon Sep 7 05:17:03 PDT 2026


On 9/7/2026 1:42 PM, Donggeun Yoo wrote:
> A program acting as exception boundary saves all callee-saved registers,
> so build_prologue() takes the exception_cb path and never calls
> push_callee_regs(). That is the only place find_used_callee_regs() runs,
> and with it the only place ctx->fp_used is set, so the callback prologue
> does not emit the
> 
>    mov x25, sp
> 
> that points BPF_REG_FP at the frame the callback runs on. x25 keeps
> whatever it held when bpf_throw() was called. If the throw came from a
> subprogram that uses its own BPF stack, that is the subprogram's frame
> pointer, and since the subprogram never returns it never restores x25
> either.
> 
> Stack accesses through BPF_REG_FP are rewritten to be stack pointer
> relative, so those still land in the callback's own frame. Materializing
> the register does not: a callback that passes the address of a local
> variable to a helper hands over an address in the dead subprogram's
> frame. That address is below the callback's stack pointer by then, and
> the helper's own call chain covers it, so the helper can write over its
> own return address. 0x1234 below is the value the helper was asked to
> store:
> 
>    pc : 0x1234
>    lr : 0x1234
>    Call trace:
>     0x1234 (P)
>     bpf_test_run+0x188/0x3e0
>     bpf_prog_test_run_skb+0x47c/0x998
>     __sys_bpf+0xbdc/0xdd8
>    Kernel panic - not syncing: Oops: Fatal exception in interrupt
> 
> Set ctx->fp_used on the exception callback path so that the existing code
> further down sets x25 from the stack pointer. The epilogue restores it
> from the main program's save area along with the other callee-saved
> registers, as it already does. x86 sets the frame pointer for the
> callback from the argument it is passed, and powerpc computes it from
> the stack pointer.
> 
> Fixes: 5d4fa9ec5643 ("bpf, arm64: Avoid blindly saving/restoring all callee-saved registers")
> Signed-off-by: Donggeun Yoo <donggeunyoo.kernel at gmail.com>
> ---
>   arch/arm64/net/bpf_jit_comp.c | 2 ++
>   1 file changed, 2 insertions(+)
> 
> diff --git a/arch/arm64/net/bpf_jit_comp.c b/arch/arm64/net/bpf_jit_comp.c
> index c18e005a41db..c5f55d6161fe 100644
> --- a/arch/arm64/net/bpf_jit_comp.c
> +++ b/arch/arm64/net/bpf_jit_comp.c
> @@ -600,6 +600,8 @@ static int build_prologue(struct jit_ctx *ctx, bool ebpf_from_cbpf)
>   		 * 12 registers are on the stack
>   		 */
>   		emit(A64_SUB_I(1, A64_SP, A64_FP, 96), ctx);
> +		/* The callback may use its own BPF stack, set up fp for it. */
> +		ctx->fp_used = true;
Right, every path in the prologue that backs x25 on the stack should also
set fp_used=true.

Acked-by: Xu Kuohai <xukuohai at huawei.com>

>   	}
>   
>   	/* Stack must be multiples of 16B */




More information about the linux-arm-kernel mailing list