Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

s390/bpf: Fix clobbering the caller's backchain in the trampoline

One of the first things that s390x kernel functions do is storing the
the caller's frame address (backchain) on stack. This makes unwinding
possible. The backchain is always stored at frame offset 152, which is
inside the 160-byte stack area, that the functions allocate for their
callees. The callees must preserve the backchain; the remaining 152
bytes they may use as they please.

Currently the trampoline uses all 160 bytes, clobbering the backchain.
This causes kernel panics when using __builtin_return_address() in
functions called by the trampoline.

Fix by reducing the usage of the caller-reserved stack area by 8 bytes
in the trampoline.

Fixes: 528eb2cb87bc ("s390/bpf: Implement arch_prepare_bpf_trampoline()")
Reported-by: Song Liu <song@kernel.org>
Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20231010203512.385819-2-iii@linux.ibm.com

authored by

Ilya Leoshkevich and committed by
Daniel Borkmann
ce10fc06 57ddeb86

+6 -2
+6 -2
arch/s390/net/bpf_jit_comp.c
··· 2260 2260 tjit->run_ctx_off = alloc_stack(tjit, 2261 2261 sizeof(struct bpf_tramp_run_ctx)); 2262 2262 tjit->tccnt_off = alloc_stack(tjit, sizeof(u64)); 2263 - /* The caller has already reserved STACK_FRAME_OVERHEAD bytes. */ 2264 - tjit->stack_size -= STACK_FRAME_OVERHEAD; 2263 + /* 2264 + * In accordance with the s390x ABI, the caller has allocated 2265 + * STACK_FRAME_OVERHEAD bytes for us. 8 of them contain the caller's 2266 + * backchain, and the rest we can use. 2267 + */ 2268 + tjit->stack_size -= STACK_FRAME_OVERHEAD - sizeof(u64); 2265 2269 tjit->orig_stack_args_off = tjit->stack_size + STACK_FRAME_OVERHEAD; 2266 2270 2267 2271 /* aghi %r15,-stack_size */