[PATCH bpf v2 1/2] bpf, arm64: set up the frame pointer for the exception callback
Xu Kuohai
xukuohai at huaweicloud.com
Mon Sep 7 05:17:03 PDT 2026
On 9/7/2026 1:42 PM, Donggeun Yoo wrote:
> A program acting as exception boundary saves all callee-saved registers,
> so build_prologue() takes the exception_cb path and never calls
> push_callee_regs(). That is the only place find_used_callee_regs() runs,
> and with it the only place ctx->fp_used is set, so the callback prologue
> does not emit the
>
> mov x25, sp
>
> that points BPF_REG_FP at the frame the callback runs on. x25 keeps
> whatever it held when bpf_throw() was called. If the throw came from a
> subprogram that uses its own BPF stack, that is the subprogram's frame
> pointer, and since the subprogram never returns it never restores x25
> either.
>
> Stack accesses through BPF_REG_FP are rewritten to be stack pointer
> relative, so those still land in the callback's own frame. Materializing
> the register does not: a callback that passes the address of a local
> variable to a helper hands over an address in the dead subprogram's
> frame. That address is below the callback's stack pointer by then, and
> the helper's own call chain covers it, so the helper can write over its
> own return address. 0x1234 below is the value the helper was asked to
> store:
>
> pc : 0x1234
> lr : 0x1234
> Call trace:
> 0x1234 (P)
> bpf_test_run+0x188/0x3e0
> bpf_prog_test_run_skb+0x47c/0x998
> __sys_bpf+0xbdc/0xdd8
> Kernel panic - not syncing: Oops: Fatal exception in interrupt
>
> Set ctx->fp_used on the exception callback path so that the existing code
> further down sets x25 from the stack pointer. The epilogue restores it
> from the main program's save area along with the other callee-saved
> registers, as it already does. x86 sets the frame pointer for the
> callback from the argument it is passed, and powerpc computes it from
> the stack pointer.
>
> Fixes: 5d4fa9ec5643 ("bpf, arm64: Avoid blindly saving/restoring all callee-saved registers")
> Signed-off-by: Donggeun Yoo <donggeunyoo.kernel at gmail.com>
> ---
> arch/arm64/net/bpf_jit_comp.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/arch/arm64/net/bpf_jit_comp.c b/arch/arm64/net/bpf_jit_comp.c
> index c18e005a41db..c5f55d6161fe 100644
> --- a/arch/arm64/net/bpf_jit_comp.c
> +++ b/arch/arm64/net/bpf_jit_comp.c
> @@ -600,6 +600,8 @@ static int build_prologue(struct jit_ctx *ctx, bool ebpf_from_cbpf)
> * 12 registers are on the stack
> */
> emit(A64_SUB_I(1, A64_SP, A64_FP, 96), ctx);
> + /* The callback may use its own BPF stack, set up fp for it. */
> + ctx->fp_used = true;
Right, every path in the prologue that backs x25 on the stack should also
set fp_used=true.
Acked-by: Xu Kuohai <xukuohai at huawei.com>
> }
>
> /* Stack must be multiples of 16B */
More information about the linux-arm-kernel
mailing list