python / python/cpython

AArch64 JIT trampoline clobbers x8

Ouverte
#157,510 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

interpreter-core topic-JIT type-bug
Langage dominant
Python
Étoiles
77.2k
Forks
35.9k
Métriques de merge des PR
Métriques de PR en attente

Description

Bug report

Bug description:

While auditing the indirect branches the JIT emits on AArch64 for BTI compatibility (part of investigating gh-149697), I noticed that the trampoline for calls out of range of a bl (patch_aarch64_trampoline in Python/jit.c) is:

ldr x8, 8
br  x8

The AAPCS64 only allows a veneer to alter x16, x17 and the flags, which is why the linkers' own long-branch stubs use x16. x8 carries the address of the result buffer when the callee returns a struct too large for registers, so a callee reached through this trampoline would store its result through the trampoline's target address instead.

THere is no helper at the moment where a JIT call would return such a struct but a standalone program calling a function that returns a 32-byte struct through the same 16 bytes segfaults with x8 and works with x16. A simple reproducer:

#include <stdio.h>

typedef struct { long a, b, c, d; } big;   /* returned through x8 */

big make_big(long x) { return (big){x, x + 1, x + 2, x + 3}; }

/* trampolines */
__asm__(
    "via_x8:  ldr x8, 1f\n  br x8\n  1: .xword make_big\n"
    "via_x16: ldr x16, 2f\n br x16\n 2: .xword make_big\n"
);
big via_x8(long), via_x16(long);

int main(void)
{
    big r = via_x16(40);
    printf("via x16: %ld %ld %ld %ld\n", r.a, r.b, r.c, r.d);
    fflush(stdout);
    r = via_x8(40);
    printf("via x8:  %ld %ld %ld %ld\n", r.a, r.b, r.c, r.d);
}
$ gcc -O2 -g repro.c && ./a.out
via x16: 40 41 42 43
Segmentation fault (core dumped)

Using x16 also makes the br acceptable to a BTI C landing pad once JIT memory is mapped with PROT_BTI, which the linkers' stubs already satisfy.

Introduced in gh-119726.

cc @diegorusso

CPython versions tested on:

CPython main branch, 3.16, 3.15, 3.14

Operating systems tested on:

Linux

Linked PRs
  • gh-157527

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Commencez dans Python/jit.c, au niveau de patch_aarch64_trampoline, puis exécutez le reproducer AArch64 en C fourni pour observer l’échec de x8. Vérifiez les contraintes AAPCS64 et BTI décrites dans le rapport ; le travail est terminé lorsque le trampoline n’écrase plus le registre du tampon de résultat de la grande structure et que le reproducer réussit.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
c, python
Domaine
compilers
Type d'issue
Bug
Difficulté
3/5
Temps estimé
1-2 jours
Activité
À l'abandon
Clarté
Clairement spécifiée
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.