The arm64 JIT does not set BPF_REG_FP in the prologue of an exception
callback, so the callback runs with whatever x25 held when bpf_throw()
was called. A callback that materializes the register, for instance to
pass the address of a local variable to a helper, then works on the
frame of the subprogram that threw.
Patch 1 sets ctx->fp_used on that path, the same fix commit b114fcee766d
("bpf, arm64: Fix fp initialization for exception boundary") made for
the exception boundary. Patch 2 adds a selftest that reaches the case.
Tested on aarch64 under QEMU with vmtest.sh. Without patch 1 the new
test panics the kernel, because the address handed to the helper lands
on the helper's own saved return address:
pc : 0x1234
lr : 0x1234
Call trace:
0x1234 (P)
bpf_test_run+0x188/0x3e0
bpf_prog_test_run_skb+0x47c/0x998
__sys_bpf+0xbdc/0xdd8
Kernel panic - not syncing: Oops: Fatal exception in interrupt
With patch 1 applied the whole group passes:
#116/11 exceptions/exception_throw_subprog_stack_cb:OK
#116 exceptions:OK
Summary: 1/118 PASSED, 0 SKIPPED, 0/0 FAILED
Not tested on other architectures.
Donggeun Yoo (2):
bpf, arm64: set up the frame pointer for the exception callback
selftests/bpf: cover the exception callback using its own BPF stack
arch/arm64/net/bpf_jit_comp.c | 2 ++
.../selftests/bpf/prog_tests/exceptions.c | 1 +
.../testing/selftests/bpf/progs/exceptions.c | 29 +++++++++++++++++++
3 files changed, 32 insertions(+)
--
2.53.0