mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH bpf 0/2] LoongArch: BPF: Fix tail call count handling
@ 2026-06-25  8:32 George Guo
  2026-06-25  8:32 ` [PATCH bpf 1/2] LoongArch: BPF: Fix tail call count pointer offset for arena programs George Guo
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: George Guo @ 2026-06-25  8:32 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Huacai Chen, Tiezhu Yang, Hengqi Chen
  Cc: WANG Xuerui, Martin KaFai Lau, Eduard Zingerman,
	Kumar Kartikeya Dwivedi, Song Liu, Yonghong Song, Jiri Olsa,
	George Guo, bpf, loongarch, linux-kernel

Two independent fixes for the LoongArch BPF JIT's tail call count (TCC)
handling, both found while enabling the arena and tailcall selftests on
LoongArch.

Patch 1 fixes memory corruption / a kernel panic. For an arena program the
extra REG_ARENA slot in the prologue shifts the callee-saved area down by
one word, but BPF_TAIL_CALL_CNT_PTR_STACK_OFF() did not account for it, so
on every tail call or bpf2bpf call the JIT loaded the counter *value* and
dereferenced it as the TCC pointer.

Patch 2 fixes an off-by-one: emit_bpf_tail_call() increments the tail call
count before the NULL-slot check, so jumping through an empty prog_array
slot is charged against MAX_TAIL_CALL_CNT and programs reach the limit one
call early.

Both carry Fixes: tags and Cc: stable. They touch only emit_bpf_tail_call()
and the new offset helper; there is no functional dependency between them.

George Guo (2):
  LoongArch: BPF: Fix tail call count pointer offset for arena programs
  LoongArch: BPF: Don't charge an empty prog_array slot to the tail call
    count

 arch/loongarch/net/bpf_jit.c | 34 +++++++++++++++++++++++++++++-----
 1 file changed, 29 insertions(+), 5 deletions(-)

-- 
2.25.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH bpf 1/2] LoongArch: BPF: Fix tail call count pointer offset for arena programs
  2026-06-25  8:32 [PATCH bpf 0/2] LoongArch: BPF: Fix tail call count handling George Guo
@ 2026-06-25  8:32 ` George Guo
  2026-06-25  8:32 ` [PATCH bpf 2/2] LoongArch: BPF: Don't charge an empty prog_array slot to the tail call count George Guo
  2026-06-29  8:55 ` [PATCH bpf v2] LoongArch: BPF: Fix tail call count pointer offset for arena programs George Guo
  2 siblings, 0 replies; 5+ messages in thread
From: George Guo @ 2026-06-25  8:32 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Huacai Chen, Tiezhu Yang, Hengqi Chen
  Cc: WANG Xuerui, Martin KaFai Lau, Eduard Zingerman,
	Kumar Kartikeya Dwivedi, Song Liu, Yonghong Song, Jiri Olsa,
	George Guo, bpf, loongarch, linux-kernel, stable

From: George Guo <guodongtai@kylinos.cn>

The tail call count (TCC) and its pointer occupy the two deepest slots of
the callee-saved area set up by build_prologue(). An arena program reserves
one extra word for REG_ARENA (arena_vm_start) right above them:

    ra fp s0 s1 s2 s3 s4 s5      <- 8 words
    [ REG_ARENA ]                <- only if ctx->arena_vm_start
    tail_call_cnt
    tail_call_cnt_ptr            <- loaded on tail call / bpf2bpf call

BPF_TAIL_CALL_CNT_PTR_STACK_OFF() hardcodes the pointer at
round_up(stack, 16) - 80, which is only correct when REG_ARENA is absent.
For an arena program the extra word shifts every slot below it down by 8
bytes, so the macro resolves to the tail_call_cnt slot (the counter value)
instead of tail_call_cnt_ptr. The JIT then loads that small integer and
dereferences it as the TCC pointer, corrupting memory or panicking the
kernel whenever an arena program performs a tail call or a bpf2bpf call.

Replace the macro with a helper that accounts for the REG_ARENA slot,
mirroring the reservation logic in build_prologue().

Fixes: ef54c517a937 ("LoongArch: BPF: Implement PROBE_MEM32 pseudo instructions")
Cc: stable@vger.kernel.org
Signed-off-by: George Guo <guodongtai@kylinos.cn>
---
 arch/loongarch/net/bpf_jit.c | 22 +++++++++++++++++++---
 1 file changed, 19 insertions(+), 3 deletions(-)

diff --git a/arch/loongarch/net/bpf_jit.c b/arch/loongarch/net/bpf_jit.c
index 24913dc7f4e8..f705de099f23 100644
--- a/arch/loongarch/net/bpf_jit.c
+++ b/arch/loongarch/net/bpf_jit.c
@@ -18,7 +18,23 @@
 
 #define REG_TCC		LOONGARCH_GPR_A6
 #define REG_ARENA	LOONGARCH_GPR_S6 /* For storing arena_vm_start */
-#define BPF_TAIL_CALL_CNT_PTR_STACK_OFF(stack) (round_up(stack, 16) - 80)
+
+static int tail_call_cnt_ptr_stack_off(struct jit_ctx *ctx)
+{
+	/* Ten words are pushed below the BPF stack: ra, fp, s0-s5, and the
+	 * tail call count plus its pointer, which occupy the two deepest
+	 * slots of the callee-saved area.
+	 */
+	int offset = sizeof(long) * 10;
+
+	/* An arena program reserves one extra word above them (REG_ARENA),
+	 * which pushes the tail call count pointer down by one slot.
+	 */
+	if (ctx->arena_vm_start)
+		offset += sizeof(long);
+
+	return round_up(ctx->stack_size, 16) - offset;
+}
 
 static const int regmap[] = {
 	/* return value from in-kernel function, and exit value for eBPF program */
@@ -278,7 +294,7 @@ bool bpf_jit_supports_far_kfunc_call(void)
 static int emit_bpf_tail_call(struct jit_ctx *ctx, int insn)
 {
 	int off, tc_ninsn = 0;
-	int tcc_ptr_off = BPF_TAIL_CALL_CNT_PTR_STACK_OFF(ctx->stack_size);
+	int tcc_ptr_off = tail_call_cnt_ptr_stack_off(ctx);
 	u8 a1 = LOONGARCH_GPR_A1;
 	u8 a2 = LOONGARCH_GPR_A2;
 	u8 t1 = LOONGARCH_GPR_T1;
@@ -1153,7 +1169,7 @@ static int build_insn(const struct bpf_insn *insn, struct jit_ctx *ctx, bool ext
 			return ret;
 
 		if (insn->src_reg == BPF_PSEUDO_CALL) {
-			tcc_ptr_off = BPF_TAIL_CALL_CNT_PTR_STACK_OFF(ctx->stack_size);
+			tcc_ptr_off = tail_call_cnt_ptr_stack_off(ctx);
 			emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, tcc_ptr_off);
 		}
 
-- 
2.25.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH bpf 2/2] LoongArch: BPF: Don't charge an empty prog_array slot to the tail call count
  2026-06-25  8:32 [PATCH bpf 0/2] LoongArch: BPF: Fix tail call count handling George Guo
  2026-06-25  8:32 ` [PATCH bpf 1/2] LoongArch: BPF: Fix tail call count pointer offset for arena programs George Guo
@ 2026-06-25  8:32 ` George Guo
  2026-06-29  8:55 ` [PATCH bpf v2] LoongArch: BPF: Fix tail call count pointer offset for arena programs George Guo
  2 siblings, 0 replies; 5+ messages in thread
From: George Guo @ 2026-06-25  8:32 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Huacai Chen, Tiezhu Yang, Hengqi Chen
  Cc: WANG Xuerui, Martin KaFai Lau, Eduard Zingerman,
	Kumar Kartikeya Dwivedi, Song Liu, Yonghong Song, Jiri Olsa,
	George Guo, bpf, loongarch, linux-kernel, stable

From: George Guo <guodongtai@kylinos.cn>

emit_bpf_tail_call() bumped the tail call count and stored it back to
*tcc_ptr before loading array->ptrs[index] and testing it for NULL.  A
tail call that targets an empty slot therefore consumed one unit of the
tail call budget even though control never transferred.

The interpreter increments tail_call_cnt only after the prog pointer is
found to be non-NULL (kernel/bpf/core.c, BPF_TAIL_CALL), so a fall-through
to an empty slot leaves the count untouched.  The JIT must do the same.

This is visible with selftests/bpf tailcalls/tailcall_3, whose entry prog
tail-calls an empty slot before the real target: the observed count is 32
instead of the expected 33.

Defer the store of the bumped count until after the NULL check.  The limit
comparison is unchanged: t3 = *tcc_ptr + 1, and "t3 > MAX_TAIL_CALL_CNT" is
equivalent to "*tcc_ptr >= MAX_TAIL_CALL_CNT".

The check-before-NULL ordering dates back to the original JIT; commit
c0fcc955ff82 ("LoongArch: BPF: Fix the tailcall hierarchy") reworked the
counter into the *tcc_ptr form but preserved the same ordering.

Fixes: 5dc615520c4d ("LoongArch: Add BPF JIT support")
Cc: stable@vger.kernel.org
Signed-off-by: George Guo <guodongtai@kylinos.cn>
---
 arch/loongarch/net/bpf_jit.c | 12 ++++++++++--
 1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/arch/loongarch/net/bpf_jit.c b/arch/loongarch/net/bpf_jit.c
index f705de099f23..f2aa0b7f65ad 100644
--- a/arch/loongarch/net/bpf_jit.c
+++ b/arch/loongarch/net/bpf_jit.c
@@ -323,13 +323,18 @@ static int emit_bpf_tail_call(struct jit_ctx *ctx, int insn)
 		goto toofar;
 
 	/*
-	 * if ((*tcc_ptr)++ >= MAX_TAIL_CALL_CNT)
+	 * if (*tcc_ptr + 1 > MAX_TAIL_CALL_CNT)
 	 *      goto out;
+	 *
+	 * Compute the bumped count but do not write it back yet: the
+	 * interpreter increments tail_call_cnt only after the prog pointer is
+	 * found to be non-NULL, so a tail call to an empty slot must not
+	 * consume the tail call budget.  The store is deferred until the call
+	 * is known to be taken (below).
 	 */
 	emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, tcc_ptr_off);
 	emit_insn(ctx, ldd, t3, REG_TCC, 0);
 	emit_insn(ctx, addid, t3, t3, 1);
-	emit_insn(ctx, std, t3, REG_TCC, 0);
 	emit_insn(ctx, addid, t2, LOONGARCH_GPR_ZERO, MAX_TAIL_CALL_CNT);
 	if (emit_tailcall_jmp(ctx, BPF_JSGT, t3, t2, jmp_offset) < 0)
 		goto toofar;
@@ -346,6 +351,9 @@ static int emit_bpf_tail_call(struct jit_ctx *ctx, int insn)
 	if (emit_tailcall_jmp(ctx, BPF_JEQ, t2, LOONGARCH_GPR_ZERO, jmp_offset) < 0)
 		goto toofar;
 
+	/* (*tcc_ptr)++; the tail call is taken, so commit the bumped count */
+	emit_insn(ctx, std, t3, REG_TCC, 0);
+
 	/* goto *(prog->bpf_func + 4); */
 	off = offsetof(struct bpf_prog, bpf_func);
 	emit_insn(ctx, ldd, t3, t2, off);
-- 
2.25.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH bpf v2] LoongArch: BPF: Fix tail call count pointer offset for arena programs
  2026-06-25  8:32 [PATCH bpf 0/2] LoongArch: BPF: Fix tail call count handling George Guo
  2026-06-25  8:32 ` [PATCH bpf 1/2] LoongArch: BPF: Fix tail call count pointer offset for arena programs George Guo
  2026-06-25  8:32 ` [PATCH bpf 2/2] LoongArch: BPF: Don't charge an empty prog_array slot to the tail call count George Guo
@ 2026-06-29  8:55 ` George Guo
  2026-07-06  7:30   ` Tiezhu Yang
  2 siblings, 1 reply; 5+ messages in thread
From: George Guo @ 2026-06-29  8:55 UTC (permalink / raw)
  To: Huacai Chen, Tiezhu Yang, Hengqi Chen, Alexei Starovoitov,
	Daniel Borkmann, Andrii Nakryiko
  Cc: WANG Xuerui, Martin KaFai Lau, Eduard Zingerman, George Guo, bpf,
	loongarch, linux-kernel, stable

From: George Guo <guodongtai@kylinos.cn>

The tail call count (TCC) and its pointer occupy the two deepest slots of
the callee-saved area set up by build_prologue(). An arena program reserves
one extra word for REG_ARENA (arena_vm_start) right above them:

    ra fp s0 s1 s2 s3 s4 s5      <- 8 words
    [ REG_ARENA ]                <- only if ctx->arena_vm_start
    tail_call_cnt
    tail_call_cnt_ptr            <- loaded on tail call / bpf2bpf call

BPF_TAIL_CALL_CNT_PTR_STACK_OFF() hardcodes the pointer at
round_up(stack, 16) - 80, which is only correct when REG_ARENA is absent.
For an arena program the extra word shifts every slot below it down by 8
bytes, so the macro resolves to the tail_call_cnt slot (the counter value)
instead of tail_call_cnt_ptr. The JIT then loads the counter value and
dereferences it as the TCC pointer, corrupting memory or panicking the
kernel whenever an arena program performs a tail call or a bpf2bpf call.

Replace the macro with a helper that accounts for the REG_ARENA slot,
mirroring the reservation logic in build_prologue().

Fixes: ef54c517a937 ("LoongArch: BPF: Implement PROBE_MEM32 pseudo instructions")
Cc: stable@vger.kernel.org
Signed-off-by: George Guo <guodongtai@kylinos.cn>
---
v2:
 - Dropped the second patch ("Don't charge an empty prog_array slot to
   the tail call count"); that off-by-one was fixed independently by
   commit 0379d10f09bc ("LoongArch: BPF: Fix off-by-one error in tail
   call"), now in 7.2-rc1. The arena tail call count pointer offset bug
   addressed here is independent and still unfixed.
 - No code change; reworded the commit message and rebased on 7.2-rc1.
 - v1: https://lore.kernel.org/all/20260625083212.277417-1-dongtai.guo@linux.dev

 arch/loongarch/net/bpf_jit.c | 22 +++++++++++++++++++---
 1 file changed, 19 insertions(+), 3 deletions(-)

diff --git a/arch/loongarch/net/bpf_jit.c b/arch/loongarch/net/bpf_jit.c
index ad7e28375aa9..5e34e9e3f508 100644
--- a/arch/loongarch/net/bpf_jit.c
+++ b/arch/loongarch/net/bpf_jit.c
@@ -25,7 +25,23 @@
 
 #define REG_TCC		LOONGARCH_GPR_A6
 #define REG_ARENA	LOONGARCH_GPR_S6 /* For storing arena_vm_start */
-#define BPF_TAIL_CALL_CNT_PTR_STACK_OFF(stack) (round_up(stack, 16) - 80)
+
+static int tail_call_cnt_ptr_stack_off(struct jit_ctx *ctx)
+{
+	/* Ten words are pushed below the BPF stack: ra, fp, s0-s5, and the
+	 * tail call count plus its pointer, which occupy the two deepest
+	 * slots of the callee-saved area.
+	 */
+	int offset = sizeof(long) * 10;
+
+	/* An arena program reserves one extra word above them (REG_ARENA),
+	 * which pushes the tail call count pointer down by one slot.
+	 */
+	if (ctx->arena_vm_start)
+		offset += sizeof(long);
+
+	return round_up(ctx->stack_size, 16) - offset;
+}
 
 static const int regmap[] = {
 	/* return value from in-kernel function, and exit value for eBPF program */
@@ -291,7 +307,7 @@ bool bpf_jit_supports_far_kfunc_call(void)
 static int emit_bpf_tail_call(struct jit_ctx *ctx, int insn)
 {
 	int off, tc_ninsn = 0;
-	int tcc_ptr_off = BPF_TAIL_CALL_CNT_PTR_STACK_OFF(ctx->stack_size);
+	int tcc_ptr_off = tail_call_cnt_ptr_stack_off(ctx);
 	u8 a1 = LOONGARCH_GPR_A1;
 	u8 a2 = LOONGARCH_GPR_A2;
 	u8 t1 = LOONGARCH_GPR_T1;
@@ -1181,7 +1197,7 @@ static int build_insn(const struct bpf_insn *insn, struct jit_ctx *ctx, bool ext
 			return ret;
 
 		if (insn->src_reg == BPF_PSEUDO_CALL) {
-			tcc_ptr_off = BPF_TAIL_CALL_CNT_PTR_STACK_OFF(ctx->stack_size);
+			tcc_ptr_off = tail_call_cnt_ptr_stack_off(ctx);
 			emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, tcc_ptr_off);
 		}
 
-- 
2.25.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH bpf v2] LoongArch: BPF: Fix tail call count pointer offset for arena programs
  2026-06-29  8:55 ` [PATCH bpf v2] LoongArch: BPF: Fix tail call count pointer offset for arena programs George Guo
@ 2026-07-06  7:30   ` Tiezhu Yang
  0 siblings, 0 replies; 5+ messages in thread
From: Tiezhu Yang @ 2026-07-06  7:30 UTC (permalink / raw)
  To: George Guo, Huacai Chen, Hengqi Chen, Alexei Starovoitov,
	Daniel Borkmann, Andrii Nakryiko
  Cc: WANG Xuerui, Martin KaFai Lau, Eduard Zingerman, George Guo, bpf,
	loongarch, linux-kernel, stable

On 2026/6/29 下午4:55, George Guo wrote:
> From: George Guo <guodongtai@kylinos.cn>
> 
> The tail call count (TCC) and its pointer occupy the two deepest slots of
> the callee-saved area set up by build_prologue(). An arena program reserves
> one extra word for REG_ARENA (arena_vm_start) right above them:
> 
>      ra fp s0 s1 s2 s3 s4 s5      <- 8 words
>      [ REG_ARENA ]                <- only if ctx->arena_vm_start
>      tail_call_cnt
>      tail_call_cnt_ptr            <- loaded on tail call / bpf2bpf call
> 
> BPF_TAIL_CALL_CNT_PTR_STACK_OFF() hardcodes the pointer at
> round_up(stack, 16) - 80, which is only correct when REG_ARENA is absent.
> For an arena program the extra word shifts every slot below it down by 8
> bytes, so the macro resolves to the tail_call_cnt slot (the counter value)
> instead of tail_call_cnt_ptr. The JIT then loads the counter value and
> dereferences it as the TCC pointer, corrupting memory or panicking the
> kernel whenever an arena program performs a tail call or a bpf2bpf call.
> 
> Replace the macro with a helper that accounts for the REG_ARENA slot,
> mirroring the reservation logic in build_prologue().
> 
> Fixes: ef54c517a937 ("LoongArch: BPF: Implement PROBE_MEM32 pseudo instructions")
> Cc: stable@vger.kernel.org
> Signed-off-by: George Guo <guodongtai@kylinos.cn>
> ---
> v2:
>   - Dropped the second patch ("Don't charge an empty prog_array slot to
>     the tail call count"); that off-by-one was fixed independently by
>     commit 0379d10f09bc ("LoongArch: BPF: Fix off-by-one error in tail
>     call"), now in 7.2-rc1. The arena tail call count pointer offset bug
>     addressed here is independent and still unfixed.
>   - No code change; reworded the commit message and rebased on 7.2-rc1.
>   - v1: https://lore.kernel.org/all/20260625083212.277417-1-dongtai.guo@linux.dev
> 
>   arch/loongarch/net/bpf_jit.c | 22 +++++++++++++++++++---
>   1 file changed, 19 insertions(+), 3 deletions(-)
> 
> diff --git a/arch/loongarch/net/bpf_jit.c b/arch/loongarch/net/bpf_jit.c
> index ad7e28375aa9..5e34e9e3f508 100644
> --- a/arch/loongarch/net/bpf_jit.c
> +++ b/arch/loongarch/net/bpf_jit.c
> @@ -25,7 +25,23 @@
>   
>   #define REG_TCC		LOONGARCH_GPR_A6
>   #define REG_ARENA	LOONGARCH_GPR_S6 /* For storing arena_vm_start */
> -#define BPF_TAIL_CALL_CNT_PTR_STACK_OFF(stack) (round_up(stack, 16) - 80)
> +
> +static int tail_call_cnt_ptr_stack_off(struct jit_ctx *ctx)
> +{
> +	/* Ten words are pushed below the BPF stack: ra, fp, s0-s5, and the
> +	 * tail call count plus its pointer, which occupy the two deepest
> +	 * slots of the callee-saved area.
> +	 */
> +	int offset = sizeof(long) * 10;
> +
> +	/* An arena program reserves one extra word above them (REG_ARENA),
> +	 * which pushes the tail call count pointer down by one slot.
> +	 */
> +	if (ctx->arena_vm_start)
> +		offset += sizeof(long);
> +
> +	return round_up(ctx->stack_size, 16) - offset;
> +}
>   
>   static const int regmap[] = {
>   	/* return value from in-kernel function, and exit value for eBPF program */
> @@ -291,7 +307,7 @@ bool bpf_jit_supports_far_kfunc_call(void)
>   static int emit_bpf_tail_call(struct jit_ctx *ctx, int insn)
>   {
>   	int off, tc_ninsn = 0;
> -	int tcc_ptr_off = BPF_TAIL_CALL_CNT_PTR_STACK_OFF(ctx->stack_size);
> +	int tcc_ptr_off = tail_call_cnt_ptr_stack_off(ctx);
>   	u8 a1 = LOONGARCH_GPR_A1;
>   	u8 a2 = LOONGARCH_GPR_A2;
>   	u8 t1 = LOONGARCH_GPR_T1;
> @@ -1181,7 +1197,7 @@ static int build_insn(const struct bpf_insn *insn, struct jit_ctx *ctx, bool ext
>   			return ret;
>   
>   		if (insn->src_reg == BPF_PSEUDO_CALL) {
> -			tcc_ptr_off = BPF_TAIL_CALL_CNT_PTR_STACK_OFF(ctx->stack_size);
> +			tcc_ptr_off = tail_call_cnt_ptr_stack_off(ctx);
>   			emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, tcc_ptr_off);
>   		}
>   
> 

Please see the discussion in the other thread:

https://lore.kernel.org/loongarch/d7f2c8d3-4a46-e978-5cce-f59b84e632f0@loongson.cn/

Thanks,
Tiezhu


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-07-06  7:31 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-25  8:32 [PATCH bpf 0/2] LoongArch: BPF: Fix tail call count handling George Guo
2026-06-25  8:32 ` [PATCH bpf 1/2] LoongArch: BPF: Fix tail call count pointer offset for arena programs George Guo
2026-06-25  8:32 ` [PATCH bpf 2/2] LoongArch: BPF: Don't charge an empty prog_array slot to the tail call count George Guo
2026-06-29  8:55 ` [PATCH bpf v2] LoongArch: BPF: Fix tail call count pointer offset for arena programs George Guo
2026-07-06  7:30   ` Tiezhu Yang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®