From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D6DB42DC798 for ; Sat, 7 Mar 2026 01:36:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772847391; cv=none; b=h/msARobRWmqnM4KOnupcdj5FAUmWrgyTQEQP6ctjxbMN94KV9WNte82VMKLCEYYGQ3jqE4O0tvGRQ+oY4jdAQEf2wRR8Qn9E8tqkjSWJnTSbh8qpGLIb4g+9cJ8uaeMC+hW9f/vos/y+8hcCc2P+egbh3GFmJBwHZ1CVwmCslQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772847391; c=relaxed/simple; bh=XpsCzMeM2sz6RelZjkDqe5dQBH05ZDxp/n1NiNQIUN4=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=miz4wfzDjYN9AkTL+Zq+AlNJ2XO6XpglbuyAaJO939r8t7Yln8jh3vieHChdQnLnVmgQx9fwHMgza+CtdCwihAVeDUboqZ4sWY2x/9Rcp9jClxnJnIR1z5hpExpwJZV8qcWt/mDcAYV068ZCmtbzNp72LFLBtZKNy0edjaJkxaA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MOpavggs; arc=none smtp.client-ip=209.85.214.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MOpavggs" Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2a7a9b8ed69so110124015ad.2 for ; Fri, 06 Mar 2026 17:36:29 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1772847389; x=1773452189; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:from:to:cc:subject :date:message-id:reply-to; bh=jtY9eIv1n6grxyELFx6qGVbBb/3PRRrubL9WWOp8eJ4=; b=MOpavggsM0CI3AFlV+NYVTdmwlpswPcTIg1wfuYJHbR7c1cByYBwt6bFnR7sxlBsYr 5QzE/Uu8PGJ3XQSAzrpYrqtUrwXHmUHLrv2mFgRVVYQQmwt7GGv31j3dsTyVFa28oyOS PnosE3Rt2wLTgZFVHSKOdHNv2HJqvn8XI86xh/vgCYRtY0LGWA1T03LI1EYqBTxtmvyt aueqi5zVSQNX7q6ryeXS1UQn8ky99oXJFXSogSYh+duSxbJoKTZxZRO9zTS9qFFJg8nY bKv5/sWSM9xyd80VYnjWta2KsZ5xI8BVGhA2/Y6axxLJTBBD4XO/e7FxJxz3ZHsTV4R9 uTEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772847389; x=1773452189; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=jtY9eIv1n6grxyELFx6qGVbBb/3PRRrubL9WWOp8eJ4=; b=m36HWv5tTy29vc9ubTkpkQgAY9UgDoWIbd/viraupR737+6JSYtvrcCM2LlPU0Zbon 5cvIFZzmGEShJzbbryFRYJ/EJELSbLzj9t2Lf0aSF0lg2o/faMAoJ64WGYAkbkKb97Sl OMWRe6nPtjktlzntN2ED2f6Y8CaGTJ8qX1nBIG25KDJzaho4OgKgX48cbKP6u+8xom3/ YHthcrlsR94g+cTE4iGob280Ah+j/cGmigcSUMna7px3DZOsJEWfpXIOQYIuXVOQv3X4 9vKqwtXonO/kPPsPKR/7OZHKzlvavsIwifnFqFcucPVlxOMSQEW8Gwc5LS3Ag5eyMLx9 j3yw== X-Forwarded-Encrypted: i=1; AJvYcCVnMkiWYkKoDXELe8BiokOEQcggAsl9zz0i+STFJM7ac0rGlFTSQe+6ZttqG6SjiNVONsaRLHoc3gT/evg=@vger.kernel.org X-Gm-Message-State: AOJu0YwbmHF/iay1jwRWnuK2nSwT0g/vX3+JcvvUzwEkrj3yWwrC7oBT bpVwsrNGR0n5mwWtN4yUnv6AA/yoKgYK97D23Pr+xmfPO7uK5A/K2Ls9 X-Gm-Gg: ATEYQzzUsiLKnsoUnoKaa8LeYLfpPrZ6DJ5YeDZV/1T12dH3WgyQoviXiAGIWpEa43L 3LuANNIkBsuCUxPEneqNuOjk7INdulXBjpppy9V0m4cyw0VAuxE+GLSie7WLRZ0C7gX02YwcsU8 fZUCh8WthOH1d+u44MLs7i4HPsRvCM25VIWTQN3KG95nv5iATZoBaXaZcfzLl0wm/xM5FsrgWAP 1W22rpc4ZMjWNy1ZaFCEIuy3Bkxr8EsTPxQGvKFEK71uqtj1jvvjWCRdPtrnwunKtoqmDDW3lX2 yzRna2uFnJ8wsAlqP73vwILQaaA4pJJ1Ly7ECZvD+yQQXNKt8tYougb6UKmdOIK35F6gyacAJxj E65Y4/ByQvboGpiSHto3zsEMw/zgGyz7Heevp3fXyDLb1U0p/zO1zoRnaCBLnhF7IQ8xfvmS/7v Ucq6ifPF6ZF2mS6KYO4m7ZnXdYuvYXja/JXkA6dIbmUX5tsYCOQki/fWfQBQHGOSdWkaxKX4FGd ieunmIy8IHQAE7TlNC4c38lKblbAMs= X-Received: by 2002:a17:903:388f:b0:2ae:50a3:3aa5 with SMTP id d9443c01a7336-2ae824879a7mr43068715ad.52.1772847389159; Fri, 06 Mar 2026 17:36:29 -0800 (PST) Received: from ?IPv6:2605:8d80:58a0:ac1f:d4e0:c92d:83b9:f4f5? ([2605:8d80:58a0:ac1f:d4e0:c92d:83b9:f4f5]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ae83eada11sm33195185ad.38.2026.03.06.17.36.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 06 Mar 2026 17:36:28 -0800 (PST) Message-ID: Subject: Re: [bpf-next v6 4/5] bpf, x86: Emit ENDBR for indirect jump targets From: Eduard Zingerman To: Xu Kuohai , bpf@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org Cc: Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Martin KaFai Lau , Yonghong Song , Puranjay Mohan , Anton Protopopov , Shahab Vahedi , Russell King , Tiezhu Yang , Hengqi Chen , Johan Almbladh , Paul Burton , Hari Bathini , Christophe Leroy , Naveen N Rao , Luke Nelson , Xi Wang , =?ISO-8859-1?Q?Bj=F6rn_T=F6pel?= , Pu Lehui , Ilya Leoshkevich , Heiko Carstens , Vasily Gorbik , "David S . Miller" , Wang YanQing Date: Fri, 06 Mar 2026 17:36:21 -0800 In-Reply-To: <20260306102329.2056216-5-xukuohai@huaweicloud.com> References: <20260306102329.2056216-1-xukuohai@huaweicloud.com> <20260306102329.2056216-5-xukuohai@huaweicloud.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.58.2 (3.58.2-1.fc43) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Fri, 2026-03-06 at 18:23 +0800, Xu Kuohai wrote: > From: Xu Kuohai >=20 > On CPUs that support CET/IBT, the indirect jump selftest triggers > a kernel panic because the indirect jump targets lack ENDBR > instructions. >=20 > To fix it, emit an ENDBR instruction to each indirect jump target. Since > the ENDBR instruction shifts the position of original jited instructions, > fix the instruction address calculation wherever the addresses are used. >=20 > For reference, below is a sample panic log. >=20 > Missing ENDBR: bpf_prog_2e5f1c71c13ac3e0_big_jump_table+0x97/0xe1 > ------------[ cut here ]------------ > kernel BUG at arch/x86/kernel/cet.c:133! > Oops: invalid opcode: 0000 [#1] SMP NOPTI >=20 > ... >=20 > ? 0xffffffffc00fb258 > ? bpf_prog_2e5f1c71c13ac3e0_big_jump_table+0x97/0xe1 > bpf_prog_test_run_syscall+0x110/0x2f0 > ? fdget+0xba/0xe0 > __sys_bpf+0xe4b/0x2590 > ? __kmalloc_node_track_caller_noprof+0x1c7/0x680 > ? bpf_prog_test_run_syscall+0x215/0x2f0 > __x64_sys_bpf+0x21/0x30 > do_syscall_64+0x85/0x620 > ? bpf_prog_test_run_syscall+0x1e2/0x2f0 >=20 > Fixes: 493d9e0d6083 ("bpf, x86: add support for indirect jumps") > Signed-off-by: Xu Kuohai > --- > arch/x86/net/bpf_jit_comp.c | 23 +++++++++++++++-------- > 1 file changed, 15 insertions(+), 8 deletions(-) >=20 > diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c > index 2c57ee446fc9..752331a64fc0 100644 > --- a/arch/x86/net/bpf_jit_comp.c > +++ b/arch/x86/net/bpf_jit_comp.c > @@ -1658,8 +1658,8 @@ static int emit_spectre_bhb_barrier(u8 **pprog, u8 = *ip, > return 0; > } > =20 > -static int do_jit(struct bpf_prog *bpf_prog, int *addrs, u8 *image, u8 *= rw_image, > - int oldproglen, struct jit_context *ctx, bool jmp_padding) > +static int do_jit(struct bpf_verifier_env *env, struct bpf_prog *bpf_pro= g, int *addrs, u8 *image, > + u8 *rw_image, int oldproglen, struct jit_context *ctx, bool jmp_padd= ing) > { > bool tail_call_reachable =3D bpf_prog->aux->tail_call_reachable; > struct bpf_insn *insn =3D bpf_prog->insnsi; > @@ -1743,6 +1743,11 @@ static int do_jit(struct bpf_prog *bpf_prog, int *= addrs, u8 *image, u8 *rw_image > dst_reg =3D X86_REG_R9; > } > =20 > +#ifdef CONFIG_X86_KERNEL_IBT > + if (bpf_insn_is_indirect_target(env, bpf_prog, i - 1)) > + EMIT_ENDBR(); > +#endif > + > switch (insn->code) { > /* ALU */ > case BPF_ALU | BPF_ADD | BPF_X: > @@ -2449,7 +2454,7 @@ st: if (is_imm8(insn->off)) > =20 > /* call */ > case BPF_JMP | BPF_CALL: { > - u8 *ip =3D image + addrs[i - 1]; > + u8 *ip =3D image + addrs[i - 1] + (prog - temp); Sorry, meant to reply to v5 but got distracted. It seems tedious/error prone to have this addend at each location, would it be possible to move the 'ip' variable calculation outside of the switch? It appears that at each point there would be no EMIT invocations between 'ip' computation and usage. > =20 > func =3D (u8 *) __bpf_call_base + imm32; > if (src_reg =3D=3D BPF_PSEUDO_CALL && tail_call_reachable) { > @@ -2474,7 +2479,8 @@ st: if (is_imm8(insn->off)) > if (imm32) > emit_bpf_tail_call_direct(bpf_prog, > &bpf_prog->aux->poke_tab[imm32 - 1], > - &prog, image + addrs[i - 1], > + &prog, > + image + addrs[i - 1] + (prog - temp), > callee_regs_used, > stack_depth, > ctx); > @@ -2483,7 +2489,7 @@ st: if (is_imm8(insn->off)) > &prog, > callee_regs_used, > stack_depth, > - image + addrs[i - 1], > + image + addrs[i - 1] + (prog - temp), > ctx); > break; > =20 > @@ -2648,7 +2654,8 @@ st: if (is_imm8(insn->off)) > break; > =20 > case BPF_JMP | BPF_JA | BPF_X: > - emit_indirect_jump(&prog, insn->dst_reg, image + addrs[i - 1]); > + emit_indirect_jump(&prog, insn->dst_reg, > + image + addrs[i - 1] + (prog - temp)); > break; > case BPF_JMP | BPF_JA: > case BPF_JMP32 | BPF_JA: > @@ -2738,7 +2745,7 @@ st: if (is_imm8(insn->off)) > ctx->cleanup_addr =3D proglen; > if (bpf_prog_was_classic(bpf_prog) && > !ns_capable_noaudit(&init_user_ns, CAP_SYS_ADMIN)) { > - u8 *ip =3D image + addrs[i - 1]; > + u8 *ip =3D image + addrs[i - 1] + (prog - temp); > =20 > if (emit_spectre_bhb_barrier(&prog, ip, bpf_prog)) > return -EINVAL; > @@ -3800,7 +3807,7 @@ struct bpf_prog *bpf_int_jit_compile(struct bpf_ver= ifier_env *env, struct bpf_pr > for (pass =3D 0; pass < MAX_PASSES || image; pass++) { > if (!padding && pass >=3D PADDING_PASSES) > padding =3D true; > - proglen =3D do_jit(prog, addrs, image, rw_image, oldproglen, &ctx, pad= ding); > + proglen =3D do_jit(env, prog, addrs, image, rw_image, oldproglen, &ctx= , padding); > if (proglen <=3D 0) { > out_image: > image =3D NULL;