Repository navigation
Conversation
…its. The `preserve_all` ABI specifies that a function may not clobber any registers (all registers are callee-saved). However, Cranelift has two features that cause code to be inserted into the prologue that may sometimes clobber registers: stack-limit checks, and stack probes. Both of these happen before clobbered registers are saved, so normally use caller-saved (volatile) registers. In `preserve_all`, no such registers exist. We previously used volatiles consistent with SysV/tail, erroneously assuming they would be volatile in all ABIs. (In Wasmtime, `preserve_all` is needed for the guest-debug breakpoint trampoline to which calls are patched in from sequence-point NOP areas. We don't spill registers around these areas, so all registers really must be preserved.) This PR fixes the interaction two ways: - Stack limits are simply disallowed in `preserve_all` functions. (This is compatible with Wasmtime's trampoline, the one `preserve_all` use-case we have in-tree.) - Stack probes are only supported with an "unrolled" strategy, where we decrement RSP and store to it in one-page-sized steps. This strategy does not use any registers (other than RSP) so is still safe in this context.
- riscv64 as well, same issue (need unrolled version of probetack). - Pulley: allocate appropriate amount of space, not constant 8 bytes, for preserve-all clobber-save slots.
alexcrichton
approved these changes
Oct 10, 2026
alexcrichton
enabled auto-merge
October 10, 2026 00:53
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
preserve_allABI specifies that a function may not clobber any registers (all registers are callee-saved).However, Cranelift has two features that cause code to be inserted into the prologue that may sometimes clobber registers: stack-limit checks, and stack probes. Both of these happen before clobbered registers are saved, so normally use caller-saved (volatile) registers. In
preserve_all, no such registers exist. We previously used volatiles consistent with SysV/tail, erroneously assuming they would be volatile in all ABIs.(In Wasmtime,
preserve_allis needed for the guest-debug breakpoint trampoline to which calls are patched in from sequence-point NOP areas. We don't spill registers around these areas, so all registers really must be preserved.)This PR fixes the interaction two ways:
preserve_allfunctions. (This is compatible with Wasmtime's trampoline, the onepreserve_alluse-case we have in-tree.)(Note that practically speaking, this has no current impact on Wasmtime because, in that one use-case above, the trampoline has effectively no stack frame so does not emit any stack probes. But the theoretical problem still exists and should be handled or rejected.)
This PR also fixes something else found while looking at
preserve_all: on Pulley, we need 16 bytes, not 8, to save a 128-bit vector register (!). That is a correctness bug reachable from Wasmtime, but only when doing guest debugging on Pulley, neither of which is tier-1.