* [PATCH bpf-next 1/5] bpf, riscv: Fix stack-passed arguments for indirect trampolines
2026-09-29 8:39 [PATCH bpf-next 0/5] riscv, bpf: Prepare for upcoming daily CI Pu Lehui
@ 2026-09-29 8:39 ` Pu Lehui
2026-09-29 16:28 ` Alexei Starovoitov
2026-09-29 8:39 ` [PATCH bpf-next 2/5] selftests/bpf: Set CONFIG_HZ_100 for riscv64 Pu Lehui
` (3 subsequent siblings)
4 siblings, 1 reply; 10+ messages in thread
From: Pu Lehui @ 2026-09-29 8:39 UTC (permalink / raw)
To: Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
Ihor Solodrai, Puranjay Mohan, Paul Walmsley, Palmer Dabbelt,
Alexandre Ghiti, Pu Lehui
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
store_args() reads stack-passed arguments relative to FP assuming the
trampoline was entered through the fentry call from a traced function. In
that path, the trampoline pushes the parent frame before establishing its
final FP, so the incoming stack arguments start at FP + 16.
An indirect trampoline for a struct_ops callback is called through a
function pointer. Its prologue allocates only the trampoline frame and sets
FP to the incoming SP. The RISC-V ABI places the first stack argument at
that incoming SP, so the arguments start at FP, not FP + 16. Every
stack-passed argument of a callback with more than eight argument slots is
therefore read two slots late.
Pass the prologue-dependent offset to store_args(), using zero for a direct
struct_ops trampoline and 16 for the fentry path.
Fixes: 6801b0aef79d ("riscv, bpf: Add 12-argument support for RV64 bpf trampoline")
Cc: Björn Töpel <bjorn@kernel.org>
Cc: Pu Lehui <pulehui@huawei.com>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Reviewed-by: Pu Lehui <pulehui@huawei.com>
---
arch/riscv/net/bpf_jit_comp64.c | 14 ++++++++++----
1 file changed, 10 insertions(+), 4 deletions(-)
diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
index ed0a6f871dea..b5fa6338e5eb 100644
--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -895,7 +895,8 @@ int bpf_arch_text_poke(void *ip, enum bpf_text_poke_type old_t,
return ret;
}
-static void store_args(int nr_arg_slots, int args_off, struct rv_jit_context *ctx)
+static void store_args(int nr_arg_slots, int args_off, int stack_args_off,
+ struct rv_jit_context *ctx)
{
int i;
@@ -903,8 +904,8 @@ static void store_args(int nr_arg_slots, int args_off, struct rv_jit_context *ct
if (i < RV_MAX_REG_ARGS) {
emit_sd(RV_REG_FP, -args_off, RV_REG_A0 + i, ctx);
} else {
- /* skip slots for T0 and FP of traced function */
- emit_ld(RV_REG_T1, 16 + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
+ emit_ld(RV_REG_T1, stack_args_off +
+ (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
emit_sd(RV_REG_FP, -args_off, RV_REG_T1, ctx);
}
args_off -= 8;
@@ -1190,7 +1191,12 @@ static int __arch_prepare_bpf_trampoline(struct bpf_tramp_image *im,
func_meta = nr_arg_slots;
emit_store_stack_imm64(RV_REG_T1, -func_meta_off, func_meta, ctx);
- store_args(nr_arg_slots, args_off, ctx);
+ /*
+ * A direct struct_ops call has its first stack argument at the incoming
+ * SP, which the trampoline keeps as FP. The fentry path pushes the
+ * parent frame first, so its incoming stack arguments start at FP + 16.
+ */
+ store_args(nr_arg_slots, args_off, is_struct_ops ? 0 : 16, ctx);
if (bpf_fsession_cnt(tnodes)) {
/* clear all session cookies' value */
--
2.34.1
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [PATCH bpf-next 1/5] bpf, riscv: Fix stack-passed arguments for indirect trampolines
2026-09-29 8:39 ` [PATCH bpf-next 1/5] bpf, riscv: Fix stack-passed arguments for indirect trampolines Pu Lehui
@ 2026-09-29 16:28 ` Alexei Starovoitov
0 siblings, 0 replies; 10+ messages in thread
From: Alexei Starovoitov @ 2026-09-29 16:28 UTC (permalink / raw)
To: Pu Lehui, Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Daniel Borkmann, Andrii Nakryiko, Eduard Zingerman,
Kumar Kartikeya Dwivedi, Martin KaFai Lau, Song Liu,
Yonghong Song, Jiri Olsa, Emil Tsalapatis, Ihor Solodrai,
Puranjay Mohan, Paul Walmsley, Palmer Dabbelt, Alexandre Ghiti,
Pu Lehui
On Tue, Sep 29, 2026 at 08:39 AM Pu Lehui <pulehui@huaweicloud.com> wrote:
> Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
> Reviewed-by: Pu Lehui <pulehui@huawei.com>
You're sending Kumar's patch, so it needs your SOB.
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH bpf-next 2/5] selftests/bpf: Set CONFIG_HZ_100 for riscv64
2026-09-29 8:39 [PATCH bpf-next 0/5] riscv, bpf: Prepare for upcoming daily CI Pu Lehui
2026-09-29 8:39 ` [PATCH bpf-next 1/5] bpf, riscv: Fix stack-passed arguments for indirect trampolines Pu Lehui
@ 2026-09-29 8:39 ` Pu Lehui
2026-09-29 16:29 ` Alexei Starovoitov
2026-09-29 8:39 ` [PATCH bpf-next 3/5] selftests/bpf: Use /tmp for temporary file in d_path Pu Lehui
` (2 subsequent siblings)
4 siblings, 1 reply; 10+ messages in thread
From: Pu Lehui @ 2026-09-29 8:39 UTC (permalink / raw)
To: Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
Ihor Solodrai, Puranjay Mohan, Paul Walmsley, Palmer Dabbelt,
Alexandre Ghiti, Pu Lehui
From: Pu Lehui <pulehui@huawei.com>
The setget_sockopt selftest fails on riscv64, specifically in the
TCP_BPF_DELACK_MAX and TCP_BPF_RTO_MIN sub-tests.
The test sets a socket option value in microseconds using
bpf_setsockopt() and immediately reads it back via bpf_getsockopt() to
verify that it matches. However, the kernel converts the value to
jiffies internally for storage, and converts it back to microseconds
upon retrieval. On riscv64, the default timer frequency is HZ=250 (4000
us per jiffy). When a value cannot be divided evenly (e.g. 30000 us),
quantization error occurs during these conversions:
usecs_to_jiffies(30000) -> 8 jiffies
jiffies_to_usecs(8) -> 32000 us (!= 30000 us)
This mismatch triggers an assertion failure.
Let's set CONFIG_HZ_100=y in config.riscv64 to align with other archs
and fix this issue.
Signed-off-by: Pu Lehui <pulehui@huawei.com>
---
tools/testing/selftests/bpf/config.riscv64 | 1 +
1 file changed, 1 insertion(+)
diff --git a/tools/testing/selftests/bpf/config.riscv64 b/tools/testing/selftests/bpf/config.riscv64
index 655cb05a7689..de45a76fdbcd 100644
--- a/tools/testing/selftests/bpf/config.riscv64
+++ b/tools/testing/selftests/bpf/config.riscv64
@@ -29,6 +29,7 @@ CONFIG_FRAME_POINTER=y
CONFIG_HARDLOCKUP_DETECTOR=y
CONFIG_HIGH_RES_TIMERS=y
CONFIG_HUGETLBFS=y
+CONFIG_HZ_100=y
CONFIG_INET=y
CONFIG_IP_ADVANCED_ROUTER=y
CONFIG_IP_MULTICAST=y
--
2.34.1
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [PATCH bpf-next 2/5] selftests/bpf: Set CONFIG_HZ_100 for riscv64
2026-09-29 8:39 ` [PATCH bpf-next 2/5] selftests/bpf: Set CONFIG_HZ_100 for riscv64 Pu Lehui
@ 2026-09-29 16:29 ` Alexei Starovoitov
0 siblings, 0 replies; 10+ messages in thread
From: Alexei Starovoitov @ 2026-09-29 16:29 UTC (permalink / raw)
To: Pu Lehui, Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Daniel Borkmann, Andrii Nakryiko, Eduard Zingerman,
Kumar Kartikeya Dwivedi, Martin KaFai Lau, Song Liu,
Yonghong Song, Jiri Olsa, Emil Tsalapatis, Ihor Solodrai,
Puranjay Mohan, Paul Walmsley, Palmer Dabbelt, Alexandre Ghiti,
Pu Lehui
On Tue, Sep 29, 2026 at 08:39 AM Pu Lehui <pulehui@huaweicloud.com> wrote:
> Let's set CONFIG_HZ_100=y in config.riscv64 to align with other archs
> and fix this issue.
x86 has HZ_1000 and config.ppc64el doesn't set HZ at all.
The test fails with HZ=250 on any arch.
Change 30000 to 40000 in progs/setget_sockopt.c instead ?
It converts without loss with HZ=100, 250 and 1000.
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH bpf-next 3/5] selftests/bpf: Use /tmp for temporary file in d_path
2026-09-29 8:39 [PATCH bpf-next 0/5] riscv, bpf: Prepare for upcoming daily CI Pu Lehui
2026-09-29 8:39 ` [PATCH bpf-next 1/5] bpf, riscv: Fix stack-passed arguments for indirect trampolines Pu Lehui
2026-09-29 8:39 ` [PATCH bpf-next 2/5] selftests/bpf: Set CONFIG_HZ_100 for riscv64 Pu Lehui
@ 2026-09-29 8:39 ` Pu Lehui
2026-09-29 16:29 ` Alexei Starovoitov
2026-09-29 8:39 ` [PATCH bpf-next 4/5] selftests/bpf: Update qemu config for riscv64 in vmtest.sh Pu Lehui
2026-09-29 8:39 ` [PATCH bpf-next 5/5] selftests/bpf: Update DENYLIST.riscv64 Pu Lehui
4 siblings, 1 reply; 10+ messages in thread
From: Pu Lehui @ 2026-09-29 8:39 UTC (permalink / raw)
To: Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
Ihor Solodrai, Puranjay Mohan, Paul Walmsley, Palmer Dabbelt,
Alexandre Ghiti, Pu Lehui
From: Pu Lehui <pulehui@huawei.com>
When running selftests via vmtest.sh on riscv64, the d_path test fails.
The failure occurs because the rootfs created by libbpf/ci [0] does not
mount /dev/shm, causing temporary file creation under /dev/shm to fail.
Let's switch to using /tmp instead to fix this issue.
Note that older rootfs images did not mount tmpfs on /tmp, writing
temporary files directly into the image. This has been fixed in [1] for
newly built images.
Link: https://github.com/libbpf/ci/tree/main/rootfs [0]
Link: https://github.com/libbpf/ci/commit/92caeba5960c [1]
Signed-off-by: Pu Lehui <pulehui@huawei.com>
---
tools/testing/selftests/bpf/prog_tests/d_path.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/bpf/prog_tests/d_path.c b/tools/testing/selftests/bpf/prog_tests/d_path.c
index 1a2a2f1abf03..b72825d1edee 100644
--- a/tools/testing/selftests/bpf/prog_tests/d_path.c
+++ b/tools/testing/selftests/bpf/prog_tests/d_path.c
@@ -220,7 +220,7 @@ static void test_d_path_check_types(void)
static void test_d_path_mem_access(void)
{
int localfd = -1;
- char path_template[] = "/dev/shm/d_path_loadgen.XXXXXX";
+ char path_template[] = "/tmp/d_path_loadgen.XXXXXX";
struct test_d_path__bss *bss;
struct test_d_path *skel;
--
2.34.1
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [PATCH bpf-next 3/5] selftests/bpf: Use /tmp for temporary file in d_path
2026-09-29 8:39 ` [PATCH bpf-next 3/5] selftests/bpf: Use /tmp for temporary file in d_path Pu Lehui
@ 2026-09-29 16:29 ` Alexei Starovoitov
0 siblings, 0 replies; 10+ messages in thread
From: Alexei Starovoitov @ 2026-09-29 16:29 UTC (permalink / raw)
To: Pu Lehui, Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Daniel Borkmann, Andrii Nakryiko, Eduard Zingerman,
Kumar Kartikeya Dwivedi, Martin KaFai Lau, Song Liu,
Yonghong Song, Jiri Olsa, Emil Tsalapatis, Ihor Solodrai,
Puranjay Mohan, Paul Walmsley, Palmer Dabbelt, Alexandre Ghiti,
Pu Lehui
On Tue, Sep 29, 2026 at 08:39 AM Pu Lehui <pulehui@huaweicloud.com> wrote:
> The failure occurs because the rootfs created by libbpf/ci [0] does not
> mount /dev/shm, causing temporary file creation under /dev/shm to fail.
>
> Let's switch to using /tmp instead to fix this issue.
This will break BPF CI.
The test was using /tmp up to v4 and was moved to /dev/shm in v5,
since /tmp is on 9p in BPF CI and 9p doesn't support fallocate. See
https://lore.kernel.org/all/20251206141210.3148-1-electronlsr@gmail.com/
vmtest's init mounts tmpfs at /dev/shm, /run and /mnt, but not at /tmp.
So fallocate() will return EOPNOTSUPP and d_path/check_mem_access
will fail on x86, arm64 and s390.
Mount tmpfs at /dev/shm in mkrootfs_tweak.sh like you did for /tmp in [1]
and drop this patch.
pw-bot: cr
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH bpf-next 4/5] selftests/bpf: Update qemu config for riscv64 in vmtest.sh
2026-09-29 8:39 [PATCH bpf-next 0/5] riscv, bpf: Prepare for upcoming daily CI Pu Lehui
` (2 preceding siblings ...)
2026-09-29 8:39 ` [PATCH bpf-next 3/5] selftests/bpf: Use /tmp for temporary file in d_path Pu Lehui
@ 2026-09-29 8:39 ` Pu Lehui
2026-09-29 8:39 ` [PATCH bpf-next 5/5] selftests/bpf: Update DENYLIST.riscv64 Pu Lehui
4 siblings, 0 replies; 10+ messages in thread
From: Pu Lehui @ 2026-09-29 8:39 UTC (permalink / raw)
To: Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
Ihor Solodrai, Puranjay Mohan, Paul Walmsley, Palmer Dabbelt,
Alexandre Ghiti, Pu Lehui
From: Pu Lehui <pulehui@huawei.com>
When running vmtest.sh on riscv64, the kernel panic at boot due to an
illegal instruction. This is because '-cpu rv64' only enables a baseline
set of riscv extensions, whereas the kernel or toolchain requires newer
extensions. Switch to '-cpu max' so qemu enables all supported
extensions.
Additionally, qemu's pmu emulation for riscv64 currently has issues,
causing perf_event_open-related tests to fail. Temporarily disable the
sscofpmf extension to bypass these failures for now, and will try to
investigate and address it later.
While at it, update the libbpf/ci branch in INDEX_URL from 'master' to
'main'.
Signed-off-by: Pu Lehui <pulehui@huawei.com>
---
tools/testing/selftests/bpf/vmtest.sh | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/bpf/vmtest.sh b/tools/testing/selftests/bpf/vmtest.sh
index e7e0b419a0b8..7f294794de67 100755
--- a/tools/testing/selftests/bpf/vmtest.sh
+++ b/tools/testing/selftests/bpf/vmtest.sh
@@ -39,7 +39,7 @@ riscv64)
QEMU_BINARY=qemu-system-riscv64
QEMU_CONSOLE="ttyS0,115200"
HOST_FLAGS=(-M virt -cpu host -enable-kvm -smp 8)
- CROSS_FLAGS=(-M virt -cpu rv64,sscofpmf=true -smp 8)
+ CROSS_FLAGS=(-M virt -cpu max,sscofpmf=false -smp 8)
BZIMAGE="arch/riscv/boot/Image"
ARCH="riscv"
;;
@@ -65,7 +65,7 @@ OUTPUT_DIR="$HOME/.bpf_selftests"
KCONFIG_REL_PATHS=("tools/testing/selftests/bpf/config"
"tools/testing/selftests/bpf/config.vm"
"tools/testing/selftests/bpf/config.${PLATFORM}")
-INDEX_URL="https://raw.githubusercontent.com/libbpf/ci/master/INDEX"
+INDEX_URL="https://raw.githubusercontent.com/libbpf/ci/main/INDEX"
NUM_COMPILE_JOBS="$(nproc)"
LOG_FILE_BASE="$(date +"bpf_selftests.%Y-%m-%d_%H-%M-%S")"
LOG_FILE="${LOG_FILE_BASE}.log"
--
2.34.1
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH bpf-next 5/5] selftests/bpf: Update DENYLIST.riscv64
2026-09-29 8:39 [PATCH bpf-next 0/5] riscv, bpf: Prepare for upcoming daily CI Pu Lehui
` (3 preceding siblings ...)
2026-09-29 8:39 ` [PATCH bpf-next 4/5] selftests/bpf: Update qemu config for riscv64 in vmtest.sh Pu Lehui
@ 2026-09-29 8:39 ` Pu Lehui
2026-09-29 16:29 ` Alexei Starovoitov
4 siblings, 1 reply; 10+ messages in thread
From: Pu Lehui @ 2026-09-29 8:39 UTC (permalink / raw)
To: Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
Ihor Solodrai, Puranjay Mohan, Paul Walmsley, Palmer Dabbelt,
Alexandre Ghiti, Pu Lehui
From: Pu Lehui <pulehui@huawei.com>
Add probe_user and stacktrace_build_id testcases to DENYLIST.riscv64, as
both tests currently fail due to riscv64's trap-based kprobe handling.
For probe_user, kprobes on riscv64 are handled via traps where the entry
path invokes irqentry_nmi_enter(). Because bpf_probe_write_user()
rejects execution in NMI context, the test fails. Upstream discussions
regarding NMI semantics on riscv are ongoing [0] and will be tracked.
For stacktrace_build_id, under the kprobe trap context with interrupts
disabled, bpf_get_stackid() obtains a valid build_id, but the queued
irq_work is deferred. As a result, subsequent bpf_get_stack() fails to
acquire mmap_read_trylock() and falls back to BPF_STACK_BUILD_ID_IP,
causing an inconsistency between the two results.
Link: https://lore.kernel.org/linux-riscv/20230702025708.784106-1-guoren@kernel.org [0]
Signed-off-by: Pu Lehui <pulehui@huawei.com>
---
tools/testing/selftests/bpf/DENYLIST.riscv64 | 2 ++
1 file changed, 2 insertions(+)
diff --git a/tools/testing/selftests/bpf/DENYLIST.riscv64 b/tools/testing/selftests/bpf/DENYLIST.riscv64
index ca1beae7fe8f..bce34d0c4f6e 100644
--- a/tools/testing/selftests/bpf/DENYLIST.riscv64
+++ b/tools/testing/selftests/bpf/DENYLIST.riscv64
@@ -1,2 +1,4 @@
# riscv64 deny list for BPF CI and local vmtest
exceptions # JIT does not support exceptions
+probe_user # kprobe hit in trap
+stacktrace_build_id # kprobe hit in trap
--
2.34.1
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [PATCH bpf-next 5/5] selftests/bpf: Update DENYLIST.riscv64
2026-09-29 8:39 ` [PATCH bpf-next 5/5] selftests/bpf: Update DENYLIST.riscv64 Pu Lehui
@ 2026-09-29 16:29 ` Alexei Starovoitov
0 siblings, 0 replies; 10+ messages in thread
From: Alexei Starovoitov @ 2026-09-29 16:29 UTC (permalink / raw)
To: Pu Lehui, Björn Töpel, bpf, linux-riscv, linux-kernel
Cc: Daniel Borkmann, Andrii Nakryiko, Eduard Zingerman,
Kumar Kartikeya Dwivedi, Martin KaFai Lau, Song Liu,
Yonghong Song, Jiri Olsa, Emil Tsalapatis, Ihor Solodrai,
Puranjay Mohan, Paul Walmsley, Palmer Dabbelt, Alexandre Ghiti,
Pu Lehui
On Tue, Sep 29, 2026 at 08:39 AM Pu Lehui <pulehui@huaweicloud.com> wrote:
> diff --git a/tools/testing/selftests/bpf/DENYLIST.riscv64 b/tools/testing/selftests/bpf/DENYLIST.riscv64
> @@ -1,2 +1,4 @@
> # riscv64 deny list for BPF CI and local vmtest
> exceptions # JIT does not support exceptions
> +probe_user # kprobe hit in trap
> +stacktrace_build_id # kprobe hit in trap
stacktrace_build_id is already in the generic DENYLIST.
^ permalink raw reply [flat|nested] 10+ messages in thread