* [PATCH bpf 1/1] bpf, riscv: Fix stack arguments of struct_ops trampolines
@ 2026-10-01 15:40 KaFai Wan
2026-10-02 1:13 ` KaFai Wan
0 siblings, 1 reply; 2+ messages in thread
From: KaFai Wan @ 2026-10-01 15:40 UTC (permalink / raw)
To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
Ihor Solodrai, Björn Töpel, Pu Lehui, Puranjay Mohan,
Paul Walmsley, Palmer Dabbelt, Albert Ou, Alexandre Ghiti, bpf,
linux-riscv, linux-kernel
Cc: KaFai Wan
When a struct_ops trampoline takes more than 8 arguments (up to 12), the
9th and beyond are passed on the stack. store_args() copies them into the
trampoline frame using a hard-coded FP + 16 base:
emit_ld(RV_REG_T1, 16 + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
That offset only holds for fentry trampolines, where the traced function's
T0/FP are saved at FP - 8/FP - 16 and its stack arguments start at FP + 16.
A struct_ops trampoline is called directly, so its stack arguments start at
FP + 0 and store_args() reads the wrong words. BPF programs then see garbage
for arg9 and beyond, which fails the selftest:
struct_ops_multi_args/test_trampoline_stack_args:FAIL
Pass the stack argument base offset to store_args(): 0 for struct_ops
trampolines, 16 otherwise.
Fixes: 6801b0aef79d ("riscv, bpf: Add 12-argument support for RV64 bpf trampoline")
Signed-off-by: KaFai Wan <kafai.wan@linux.dev>
---
arch/riscv/net/bpf_jit_comp64.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
index 01fe66774f02..4ae6674f58ed 100644
--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -875,7 +875,7 @@ int bpf_arch_text_poke(void *ip, enum bpf_text_poke_type old_t,
return ret;
}
-static void store_args(int nr_arg_slots, int args_off, struct rv_jit_context *ctx)
+static void store_args(int nr_arg_slots, int args_off, int stack_base, struct rv_jit_context *ctx)
{
int i;
@@ -883,8 +883,7 @@ static void store_args(int nr_arg_slots, int args_off, struct rv_jit_context *ct
if (i < RV_MAX_REG_ARGS) {
emit_sd(RV_REG_FP, -args_off, RV_REG_A0 + i, ctx);
} else {
- /* skip slots for T0 and FP of traced function */
- emit_ld(RV_REG_T1, 16 + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
+ emit_ld(RV_REG_T1, stack_base + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
emit_sd(RV_REG_FP, -args_off, RV_REG_T1, ctx);
}
args_off -= 8;
@@ -1179,7 +1178,8 @@ static int __arch_prepare_bpf_trampoline(struct bpf_tramp_image *im,
func_meta = nr_arg_slots;
emit_store_stack_imm64(RV_REG_T1, -func_meta_off, func_meta, ctx);
- store_args(nr_arg_slots, args_off, ctx);
+ /* skip slots for T0 and FP of traced function */
+ store_args(nr_arg_slots, args_off, is_struct_ops ? 0 : 16, ctx);
if (bpf_fsession_cnt(tnodes)) {
/* clear all session cookies' value */
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH bpf 1/1] bpf, riscv: Fix stack arguments of struct_ops trampolines
2026-10-01 15:40 [PATCH bpf 1/1] bpf, riscv: Fix stack arguments of struct_ops trampolines KaFai Wan
@ 2026-10-02 1:13 ` KaFai Wan
0 siblings, 0 replies; 2+ messages in thread
From: KaFai Wan @ 2026-10-02 1:13 UTC (permalink / raw)
To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
Ihor Solodrai, Björn Töpel, Pu Lehui, Puranjay Mohan,
Paul Walmsley, Palmer Dabbelt, Albert Ou, Alexandre Ghiti, bpf,
linux-riscv, linux-kernel
On Thu, 2026-10-01 at 23:40 +0800, KaFai Wan wrote:
I ran the tests yesterday and didn’t notice that Pu Lehui had already sent the same patch. Please
ignore this. Sorry for the noise.
> When a struct_ops trampoline takes more than 8 arguments (up to 12), the
> 9th and beyond are passed on the stack. store_args() copies them into the
> trampoline frame using a hard-coded FP + 16 base:
>
> emit_ld(RV_REG_T1, 16 + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
>
> That offset only holds for fentry trampolines, where the traced function's
> T0/FP are saved at FP - 8/FP - 16 and its stack arguments start at FP + 16.
> A struct_ops trampoline is called directly, so its stack arguments start at
> FP + 0 and store_args() reads the wrong words. BPF programs then see garbage
> for arg9 and beyond, which fails the selftest:
>
> struct_ops_multi_args/test_trampoline_stack_args:FAIL
>
> Pass the stack argument base offset to store_args(): 0 for struct_ops
> trampolines, 16 otherwise.
>
> Fixes: 6801b0aef79d ("riscv, bpf: Add 12-argument support for RV64 bpf trampoline")
> Signed-off-by: KaFai Wan <kafai.wan@linux.dev>
> ---
> arch/riscv/net/bpf_jit_comp64.c | 8 ++++----
> 1 file changed, 4 insertions(+), 4 deletions(-)
>
> diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
> index 01fe66774f02..4ae6674f58ed 100644
> --- a/arch/riscv/net/bpf_jit_comp64.c
> +++ b/arch/riscv/net/bpf_jit_comp64.c
> @@ -875,7 +875,7 @@ int bpf_arch_text_poke(void *ip, enum bpf_text_poke_type old_t,
> return ret;
> }
>
> -static void store_args(int nr_arg_slots, int args_off, struct rv_jit_context *ctx)
> +static void store_args(int nr_arg_slots, int args_off, int stack_base, struct rv_jit_context
> *ctx)
> {
> int i;
>
> @@ -883,8 +883,7 @@ static void store_args(int nr_arg_slots, int args_off, struct rv_jit_context
> *ct
> if (i < RV_MAX_REG_ARGS) {
> emit_sd(RV_REG_FP, -args_off, RV_REG_A0 + i, ctx);
> } else {
> - /* skip slots for T0 and FP of traced function */
> - emit_ld(RV_REG_T1, 16 + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
> + emit_ld(RV_REG_T1, stack_base + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP,
> ctx);
> emit_sd(RV_REG_FP, -args_off, RV_REG_T1, ctx);
> }
> args_off -= 8;
> @@ -1179,7 +1178,8 @@ static int __arch_prepare_bpf_trampoline(struct bpf_tramp_image *im,
> func_meta = nr_arg_slots;
> emit_store_stack_imm64(RV_REG_T1, -func_meta_off, func_meta, ctx);
>
> - store_args(nr_arg_slots, args_off, ctx);
> + /* skip slots for T0 and FP of traced function */
> + store_args(nr_arg_slots, args_off, is_struct_ops ? 0 : 16, ctx);
>
> if (bpf_fsession_cnt(tnodes)) {
> /* clear all session cookies' value */
--
Thanks,
KaFai
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-02 1:13 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01 15:40 [PATCH bpf 1/1] bpf, riscv: Fix stack arguments of struct_ops trampolines KaFai Wan
2026-10-02 1:13 ` KaFai Wan
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®