Re: [PATCH bpf 1/2] bpf, mips: Fix immediate JMP JEQ/JNE on MIPS32

From: David Laight

Date: Thu Sep 24 2026 - 04:27:01 EST


On Wed, 23 Sep 2026 12:51:57 +0200
Johan Almbladh <johan.almbladh@xxxxxxxxxxxxxxxxx> wrote:

> An addu instruction was emitted instead of addiu, causing the immediate
> value 1 to be interpreted as register $at. This made the comparison
> result invalid when the immediate operand was negative. Note that $at
> is mapped to BPF_REG_AX, which is used for constant blinding.
^^ building??

David

>
> Fix the instruction to use the immediate form.
>
> Found with test_bpf on MIPS32r1 emulated by QEMU.
>
> Fixes: eb63cfcd2ee8 ("mips, bpf: Add eBPF JIT for 32-bit MIPS")
> Signed-off-by: Johan Almbladh <johan.almbladh@xxxxxxxxxxxxxxxxx>
> ---
> arch/mips/net/bpf_jit_comp32.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/arch/mips/net/bpf_jit_comp32.c b/arch/mips/net/bpf_jit_comp32.c
> index 40a878b672f5..15a2a153dc87 100644
> --- a/arch/mips/net/bpf_jit_comp32.c
> +++ b/arch/mips/net/bpf_jit_comp32.c
> @@ -1111,7 +1111,7 @@ static void emit_jmp_i64(struct jit_context *ctx,
> emit(ctx, xor, tmp, lo(dst), tmp);
> }
> if (imm < 0) { /* Compare sign extension */
> - emit(ctx, addu, MIPS_R_T9, hi(dst), 1);
> + emit(ctx, addiu, MIPS_R_T9, hi(dst), 1);
> emit(ctx, or, tmp, tmp, MIPS_R_T9);
> } else { /* Compare zero extension */
> emit(ctx, or, tmp, tmp, hi(dst));