linux/arch
Donggeun Yoo ef1fb82f12 bpf, arm64: set up the frame pointer for the exception callback
A program acting as exception boundary saves all callee-saved registers,
so build_prologue() takes the exception_cb path and never calls
push_callee_regs(). That is the only place find_used_callee_regs() runs,
and with it the only place ctx->fp_used is set, so the callback prologue
does not emit the

  mov x25, sp

that points BPF_REG_FP at the frame the callback runs on. x25 keeps
whatever it held when bpf_throw() was called. If the throw came from a
subprogram that uses its own BPF stack, that is the subprogram's frame
pointer, and since the subprogram never returns it never restores x25
either.

Stack accesses through BPF_REG_FP are rewritten to be stack pointer
relative, so those still land in the callback's own frame. Materializing
the register does not: a callback that passes the address of a local
variable to a helper hands over an address in the dead subprogram's
frame. That address is below the callback's stack pointer by then, and
the helper's own call chain covers it, so the helper can write over its
own return address. 0x1234 below is the value the helper was asked to
store:

  pc : 0x1234
  lr : 0x1234
  Call trace:
   0x1234 (P)
   bpf_test_run+0x188/0x3e0
   bpf_prog_test_run_skb+0x47c/0x998
   __sys_bpf+0xbdc/0xdd8
  Kernel panic - not syncing: Oops: Fatal exception in interrupt

Set ctx->fp_used on the exception callback path so that the existing code
further down sets x25 from the stack pointer. The epilogue restores it
from the main program's save area along with the other callee-saved
registers, as it already does. x86 sets the frame pointer for the
callback from the argument it is passed, and powerpc computes it from
the stack pointer.

Fixes: 5d4fa9ec56 ("bpf, arm64: Avoid blindly saving/restoring all callee-saved registers")
Acked-by: Xu Kuohai <xukuohai@huawei.com>
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Link: https://lore.kernel.org/r/20260907130624.611942-2-donggeunyoo.kernel@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-13 21:59:21 -07:00
..
alpha pci-v7.3-changes 2026-08-23 12:44:10 -07:00
arc Treewide timer related cleanups: 2026-08-18 15:58:29 -07:00
arm ARM updates for 7.3-rc1 2026-08-30 09:43:01 -07:00
arm64 bpf, arm64: set up the frame pointer for the exception callback 2026-09-13 21:59:21 -07:00
csky mm.git review status for mm-hotfixes-stable..mm-stable 2026-08-20 18:17:08 -07:00
hexagon Treewide timer related cleanups: 2026-08-18 15:58:29 -07:00
loongarch kmalloc_obj conversions for v7.3-rc2 2026-09-05 20:45:18 -07:00
m68k m68knommu: updates and fixes for v7.3 2026-08-28 08:44:36 -07:00
microblaze Treewide timer related cleanups: 2026-08-18 15:58:29 -07:00
mips treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
nios2 mm.git review status for mm-hotfixes-stable..mm-stable 2026-08-20 18:17:08 -07:00
openrisc OpenRISC 7.3 updates 2026-08-30 09:26:54 -07:00
parisc parisc architecture fixes and updates for kernel v7.3-rc1: 2026-08-23 10:30:02 -07:00
powerpc treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
riscv bpf-fixes 2026-09-06 13:49:44 -07:00
s390 treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
sh gpio updates for v7.3-rc1 2026-08-19 09:10:07 -07:00
sparc mm.git review status for mm-hotfixes-stable..mm-stable 2026-08-20 18:17:08 -07:00
um um: Use asm-generic/timex.h over the host architecture one 2026-08-24 17:10:35 -07:00
x86 bpf-fixes 2026-09-06 13:49:44 -07:00
xtensa Xtensa updates for v7.3 2026-08-28 08:55:47 -07:00
.gitignore
Kconfig VDSO updates: 2026-08-18 16:56:25 -07:00