Commit 66e5eb84 authored by Johan Almbladh's avatar Johan Almbladh Committed by Daniel Borkmann
Browse files

bpf, tests: Add branch conversion JIT test



Some JITs may need to convert a conditional jump instruction to
to short PC-relative branch and a long unconditional jump, if the
PC-relative offset exceeds offset field width in the CPU instruction.
This test triggers such branch conversion on the 32-bit MIPS JIT.

Signed-off-by: default avatarJohan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: default avatarDaniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20210809091829.810076-11-johan.almbladh@anyfinetworks.com
parent e5009b46
Loading
Loading
Loading
Loading
+43 −0
Original line number Diff line number Diff line
@@ -461,6 +461,41 @@ static int bpf_fill_stxdw(struct bpf_test *self)
	return __bpf_fill_stxdw(self, BPF_DW);
}

static int bpf_fill_long_jmp(struct bpf_test *self)
{
	unsigned int len = BPF_MAXINSNS;
	struct bpf_insn *insn;
	int i;

	insn = kmalloc_array(len, sizeof(*insn), GFP_KERNEL);
	if (!insn)
		return -ENOMEM;

	insn[0] = BPF_ALU64_IMM(BPF_MOV, R0, 1);
	insn[1] = BPF_JMP_IMM(BPF_JEQ, R0, 1, len - 2 - 1);

	/*
	 * Fill with a complex 64-bit operation that expands to a lot of
	 * instructions on 32-bit JITs. The large jump offset can then
	 * overflow the conditional branch field size, triggering a branch
	 * conversion mechanism in some JITs.
	 *
	 * Note: BPF_MAXINSNS of ALU64 MUL is enough to trigger such branch
	 * conversion on the 32-bit MIPS JIT. For other JITs, the instruction
	 * count and/or operation may need to be modified to trigger the
	 * branch conversion.
	 */
	for (i = 2; i < len - 1; i++)
		insn[i] = BPF_ALU64_IMM(BPF_MUL, R0, (i << 16) + i);

	insn[len - 1] = BPF_EXIT_INSN();

	self->u.ptr.insns = insn;
	self->u.ptr.len = len;

	return 0;
}

static struct bpf_test tests[] = {
	{
		"TAX",
@@ -6895,6 +6930,14 @@ static struct bpf_test tests[] = {
		{ },
		{ { 0, 1 } },
	},
	{	/* Mainly checking JIT here. */
		"BPF_MAXINSNS: Very long conditional jump",
		{ },
		INTERNAL | FLAG_NO_DATA,
		{ },
		{ { 0, 1 } },
		.fill_helper = bpf_fill_long_jmp,
	},
	{
		"JMP_JA: Jump, gap, jump, ...",
		{ },