Skip to content

Commit a3f25d6

Browse files
ahduyckAlexei Starovoitov
authored andcommitted
bpf, arm64: Fix BTI type used for freplace attached functions
When running an freplace attached bpf program on an arm64 system w were seeing the following issue: Unhandled 64-bit el1h sync exception on CPU47, ESR 0x0000000036000003 -- BTI After a bit of work to track it down I determined that what appeared to be happening is that the 'bti c' at the start of the program was somehow being reached after a 'br' instruction. Further digging pointed me toward the fact that the function was attached via freplace. This in turn led me to build_plt which I believe is invoking the long jump which is triggering this error. To resolve it we can replace the 'bti c' with 'bti jc' and add a comment explaining why this has to be modified as such. Fixes: b2ad54e ("bpf, arm64: Implement bpf_arch_text_poke() for arm64") Signed-off-by: Alexander Duyck <[email protected]> Acked-by: Xu Kuohai <[email protected]> Link: https://lore.kernel.org/r/168926677665.316237.9953845318337455525.stgit@ahduyck-xeon-server.home.arpa Signed-off-by: Alexei Starovoitov <[email protected]>
1 parent a8237cc commit a3f25d6

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

arch/arm64/net/bpf_jit_comp.c

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,13 @@ static int build_prologue(struct jit_ctx *ctx, bool ebpf_from_cbpf)
322322
*
323323
*/
324324

325-
emit_bti(A64_BTI_C, ctx);
325+
/* bpf function may be invoked by 3 instruction types:
326+
* 1. bl, attached via freplace to bpf prog via short jump
327+
* 2. br, attached via freplace to bpf prog via long jump
328+
* 3. blr, working as a function pointer, used by emit_call.
329+
* So BTI_JC should used here to support both br and blr.
330+
*/
331+
emit_bti(A64_BTI_JC, ctx);
326332

327333
emit(A64_MOV(1, A64_R(9), A64_LR), ctx);
328334
emit(A64_NOP, ctx);

0 commit comments

Comments
 (0)