AArch64 JIT trampoline clobbers x8
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- Python
- Estrellas
- 77.2k
- Forks
- 35.9k
- Métricas de merge de PR
- Métricas de PR pendientes
Descripción
Bug report
Bug description:
While auditing the indirect branches the JIT emits on AArch64 for BTI compatibility (part of investigating gh-149697), I noticed that the trampoline for calls out of range of a bl (patch_aarch64_trampoline in Python/jit.c) is:
ldr x8, 8
br x8
The AAPCS64 only allows a veneer to alter x16, x17 and the flags, which is why the linkers' own long-branch stubs use x16. x8 carries the address of the result buffer when the callee returns a struct too large for registers, so a callee reached through this trampoline would store its result through the trampoline's target address instead.
THere is no helper at the moment where a JIT call would return such a struct but a standalone program calling a function that returns a 32-byte struct through the same 16 bytes segfaults with x8 and works with x16. A simple reproducer:
#include <stdio.h>
typedef struct { long a, b, c, d; } big; /* returned through x8 */
big make_big(long x) { return (big){x, x + 1, x + 2, x + 3}; }
/* trampolines */
__asm__(
"via_x8: ldr x8, 1f\n br x8\n 1: .xword make_big\n"
"via_x16: ldr x16, 2f\n br x16\n 2: .xword make_big\n"
);
big via_x8(long), via_x16(long);
int main(void)
{
big r = via_x16(40);
printf("via x16: %ld %ld %ld %ld\n", r.a, r.b, r.c, r.d);
fflush(stdout);
r = via_x8(40);
printf("via x8: %ld %ld %ld %ld\n", r.a, r.b, r.c, r.d);
}
$ gcc -O2 -g repro.c && ./a.out
via x16: 40 41 42 43
Segmentation fault (core dumped)
Using x16 also makes the br acceptable to a BTI C landing pad once JIT memory is mapped with PROT_BTI, which the linkers' stubs already satisfy.
Introduced in gh-119726.
cc @diegorusso
CPython versions tested on:
CPython main branch, 3.16, 3.15, 3.14
Operating systems tested on:
Linux
Linked PRs
- gh-157527
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Empieza en Python/jit.c, en patch_aarch64_trampoline, y ejecuta después el reproductor AArch64 en C proporcionado para observar el fallo de x8. Comprueba las restricciones de AAPCS64 y BTI descritas en el informe; se considera terminado cuando el trampoline ya no sobrescribe el registro del búfer de resultados de la estructura grande y el reproductor se ejecuta correctamente.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- c, python
- Área
- compilers
- Tipo de issue
- Error
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Estado de actividad
- Estancado
- Claridad
- Bien especificado
- Aptitud para principiantes
- 35/100