python / python/cpython

AArch64 JIT trampoline clobbers x8

Abierto
#157,510 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

interpreter-core topic-JIT type-bug
Lenguaje dominante
Python
Estrellas
77.2k
Forks
35.9k
Métricas de merge de PR
Métricas de PR pendientes

Descripción

Bug report

Bug description:

While auditing the indirect branches the JIT emits on AArch64 for BTI compatibility (part of investigating gh-149697), I noticed that the trampoline for calls out of range of a bl (patch_aarch64_trampoline in Python/jit.c) is:

ldr x8, 8
br  x8

The AAPCS64 only allows a veneer to alter x16, x17 and the flags, which is why the linkers' own long-branch stubs use x16. x8 carries the address of the result buffer when the callee returns a struct too large for registers, so a callee reached through this trampoline would store its result through the trampoline's target address instead.

THere is no helper at the moment where a JIT call would return such a struct but a standalone program calling a function that returns a 32-byte struct through the same 16 bytes segfaults with x8 and works with x16. A simple reproducer:

#include <stdio.h>

typedef struct { long a, b, c, d; } big;   /* returned through x8 */

big make_big(long x) { return (big){x, x + 1, x + 2, x + 3}; }

/* trampolines */
__asm__(
    "via_x8:  ldr x8, 1f\n  br x8\n  1: .xword make_big\n"
    "via_x16: ldr x16, 2f\n br x16\n 2: .xword make_big\n"
);
big via_x8(long), via_x16(long);

int main(void)
{
    big r = via_x16(40);
    printf("via x16: %ld %ld %ld %ld\n", r.a, r.b, r.c, r.d);
    fflush(stdout);
    r = via_x8(40);
    printf("via x8:  %ld %ld %ld %ld\n", r.a, r.b, r.c, r.d);
}
$ gcc -O2 -g repro.c && ./a.out
via x16: 40 41 42 43
Segmentation fault (core dumped)

Using x16 also makes the br acceptable to a BTI C landing pad once JIT memory is mapped with PROT_BTI, which the linkers' stubs already satisfy.

Introduced in gh-119726.

cc @diegorusso

CPython versions tested on:

CPython main branch, 3.16, 3.15, 3.14

Operating systems tested on:

Linux

Linked PRs
  • gh-157527

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Línea de trabajo

Empieza en Python/jit.c, en patch_aarch64_trampoline, y ejecuta después el reproductor AArch64 en C proporcionado para observar el fallo de x8. Comprueba las restricciones de AAPCS64 y BTI descritas en el informe; se considera terminado cuando el trampoline ya no sobrescribe el registro del búfer de resultados de la estructura grande y el reproductor se ejecuta correctamente.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
c, python
Área
compilers
Tipo de issue
Error
Dificultad
3/5
Tiempo estimado
1-2 días
Estado de actividad
Estancado
Claridad
Bien especificado
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.