Fix/x86 dwarf verifier - #115
Conversation
The Phase-2 `dwarf_return_addr` refactor folded the x86_64 return-address
read into a helper that borrows `&entry` and recomputes the signal-frame
check from `entry.cfa_type`. That kept the UnwindEntry spilled across the
`bpf_probe_read_user` call, and on some kernels (observed on 6.1.180,
x86_64) the verifier then rejects the program with:
invalid read from stack R10 off=-232 size=8
so `probee --dwarf` fails to load. This regressed in v0.3.22+ (release CI
builds the eBPF fresh, so shipped x86_64 binaries carry the refactor).
Restore the x86_64 return-address computation to its original inline form
(RA at CFA-8, or the signal-frame ucontext slot) — the shape the verifier
accepted for years. The `dwarf_return_addr` helper is now aarch64-only,
where it is genuinely needed (RA in LR, per-entry ra_offset rule). Both
call sites (dwarf_unwind_one_frame, dwarf_copy_stack_regs) are cfg-gated.
aarch64 DWARF unwinding is unchanged and still verifies + resolves full
no-FP chains locally. x86_64 fix validated on the reproducing host (see
follow-up). Regenerated the committed aarch64 prebuilt.
…ilt) The release workflow built the eBPF with `--manifest-path profile-bee-ebpf/Cargo.toml` from the repo root. Because profile-bee-ebpf is a separate workspace whose `.cargo/config` (target-dir = ../target) only applies when cargo runs from inside that directory, the object landed in `profile-bee-ebpf/target/` — not the `<root>/target/bpfel-unknown-none/...` path profile-bee's build.rs checks. build.rs then silently fell back to the committed prebuilt, so released x86_64 binaries shipped the stale `ebpf-bin/profile-bee.bpf.o` (v0.3.21-era) rather than a fresh build. That stale object trips the verifier on newer kernels (observed: 6.1.180 x86_64, `--dwarf` fails with "invalid read from stack"), which is the crash being reported even though the source was fixed. - release.yml: build the eBPF from inside profile-bee-ebpf (matches the CI e2e job), so build.rs picks up the fresh object. - build.rs: also look for the fresh object under profile-bee-ebpf/target so a `--manifest-path`-style build is never silently ignored again. Validated on the reporting host: with a fresh build embedded (via `cargo xtask build-ebpf`), `probee --dwarf` verifies and runs (was crashing on load). Note: the committed `ebpf-bin/profile-bee.bpf.o` is still the stale v0.3.21 object and should be regenerated on x86_64 (I can't cross-build it from aarch64). With this change, released binaries no longer depend on it; it is only a fallback for stable `cargo install`.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe release workflow now builds eBPF from ChangeseBPF build and unwind updates
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Merge Risk: ⚪ Minimal · up to This change updates eBPF artifact selection for releases and preserves architecture-specific return-address recovery behavior. No actionable merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bump workspace crates 0.3.24 -> 0.3.25. Ships the DWARF verifier fix (#115): release.yml now builds the eBPF where build.rs finds it (was silently embedding the stale committed prebuilt), build.rs also checks profile-bee-ebpf/target, and the x86_64 DWARF return-address read is back to its verifier-clean inline form. Validated on kernel 6.1.180 x86_64.
Summary by CodeRabbit
Bug Fixes
Chores