s390/bpf: Fix multiple tail calls
authorIlya Leoshkevich <iii@linux.ibm.com>
Wed, 9 Sep 2020 23:21:41 +0000 (01:21 +0200)
committerAlexei Starovoitov <ast@kernel.org>
Tue, 15 Sep 2020 01:21:31 +0000 (18:21 -0700)
commitd72714c1da138e6755d3bd14662dc5b7f17fae7f
tree2189c79bb786aa66f50823217cdc9c3e91b392fd
parent2bab48c5bef00d103085da71a01da27ec7200c08
s390/bpf: Fix multiple tail calls

In order to branch around tail calls (due to out-of-bounds index,
exceeding tail call count or missing tail call target), JIT uses
label[0] field, which contains the address of the instruction following
the tail call. When there are multiple tail calls, label[0] value comes
from handling of a previous tail call, which is incorrect.

Fix by getting rid of label array and resolving the label address
locally: for all 3 branches that jump to it, emit 0 offsets at the
beginning, and then backpatch them with the correct value.

Also, do not use the long jump infrastructure: the tail call sequence
is known to be short, so make all 3 jumps short.

Fixes: 6651ee070b31 ("s390/bpf: implement bpf_tail_call() helper")
Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20200909232141.3099367-1-iii@linux.ibm.com
arch/s390/net/bpf_jit_comp.c