fix(verify): gate JIT verification to amd64 until trampolines are hardened
Test / vet (push) Successful in 48s
Test / test (push) Successful in 2m34s
Test / build (push) Successful in 41s

This commit is contained in:
2026-08-30 22:48:48 +02:00
parent 9cb1666b35
commit a5a59d6503
15 changed files with 206 additions and 30 deletions
+10 -9
View File
@@ -364,15 +364,16 @@ and returns). A 64-byte pad below the return address accommodates the
ABIInternal wrapper that the Go runtime interposes on assembly functions.
Every supported architecture carries its own hand-written trampoline pair
(`trampoline_amd64.s`, `trampoline_arm64.s`, `trampoline_riscv64.s`,
`trampoline_loong64.s`), so `Call` works wherever the toolkit runs. The
ABI-checked variant `CallChecked` exists for every architecture too:
`enterJITChecked` plants sentinels in the registers the Go ABI fixes across
calls (amd64 `BP`/`R14`, arm64 `R29`/`R28`, riscv64 `X27`, loong64 `R22`;
the latter two keep no hardware frame pointer) and the raw return trampoline
`leaveJITCheckedRaw` verifies them, so `-abi` reports frame-pointer,
goroutine-pointer and below-SP violations on every supported host. `gasm
verify` dispatches by host: the JIT checks run when the host matches the
kernel's architecture, and only the toolchain comparisons run elsewhere.
`trampoline_loong64.s`). The ABI-checked variant `CallChecked` exists for
every architecture too: `enterJITChecked` plants sentinels in the registers
the Go ABI fixes across calls (amd64 `BP`/`R14`, arm64 `R29`/`R28`, riscv64
`X27`, loong64 `R22`; the latter two keep no hardware frame pointer) and the
raw return trampoline `leaveJITCheckedRaw` verifies them, restoring the
saved registers before Go code resumes. At present only the amd64 JIT path
is runtime-proven: the non-amd64 trampolines compile and their kernels are
correct, but the return into Go code still fails under emulation, so `gasm
verify` gates JIT execution to amd64 kernels on amd64 hosts and runs only
the toolchain comparisons elsewhere (see docs/DECISIONS.md).
`Load` / `LoadSource` / `LoadAST` parse, assemble and map a `.s` file in one
step, returning a `Kernel` whose `CallFunc` method marshals the argument block