macovedj opened PR #14516 from macovedj:fix-winch-aarch64-tail-call-sp to bytecodealliance:main:
When a function with stack arguments tail-calls a callee with no stack arguments, Winch’s AArch64 backend advances SP past the saved frame pointer before reloading it. A signal handler running between those instructions can overwrite the saved FP.
This PR computes the callee’s entry SP in a scratch register, restores FP while the old frame is still protected, and then updates SP.
Fixes #14503.
macovedj requested wasmtime-compiler-reviewers for a review on PR #14516.
macovedj requested cfallin for a review on PR #14516.
macovedj requested wasmtime-core-reviewers for a review on PR #14516.
github-actions[bot] added the label winch on PR #14516.
github-actions[bot] commented on PR #14516:
Subscribe to Label Action
cc @saulecabrera
<details>
This issue or pull request has been labeled: "winch"Thus the following users have been cc'd because of the following labels:
- saulecabrera: winch
To subscribe or unsubscribe from this label, edit the <code>.github/subscribe-to-label.json</code> configuration file.
Learn more.
</details>
:memo: saulecabrera submitted PR review.
:speech_balloon: saulecabrera created PR review comment:
I believe most of this code has a lot of commonalities with the one defined in
with_tail_call_resize? I wonder if we can add a small helper to avoid duplicating this and more importantly to avoid it drifting?
macovedj updated PR #14516.
:thumbs_up: saulecabrera submitted PR review.
saulecabrera added PR #14516 winch: restore aarch64 frame pointer before advancing SP to the merge queue.
:check: saulecabrera merged PR #14516.
saulecabrera removed PR #14516 winch: restore aarch64 frame pointer before advancing SP from the merge queue.
Last updated: Oct 11 2026 at 04:10 UTC