From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f42.google.com (mail-qv1-f42.google.com [209.85.219.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CADE63E7BD7 for ; Fri, 5 Jun 2026 14:57:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.42 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780671435; cv=none; b=kwiDf6dDAkFgdHvdf4dRl8p/Udwtz8vm0zNFdGR2ayN5VsQ3nsJxqPb8MChBLZlcGWUOpJxsT9g9w5sGXUT/9sYFxPmKTSXiVNvQ16QU8EFdv9zlCvdvWlU2EMU/TDuMD12QOAHKkBL1xL1y5OyGie8ajOvEofpHiIn6JThrp34= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780671435; c=relaxed/simple; bh=Mz8IzpA+mE1lCCJhfegzw1OtF+FGE+EqPAuT2hpR5RA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=SRqSdP7/ckKGCxPPdOOCE10RNJ3YygJFKdqzG513461JBKWTpYvf7K93cbh6RzejOVbNw7g0pDpnQChkxRh+O5YPa1H7m+BYPOPFTVQcjU2EpG3MEdl92jfX+2luYQdkY96kIHgLimt4ZHchxZfa/iqIwj0TqyWCvtdQXnQkrFs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Si1Yh1sb; arc=none smtp.client-ip=209.85.219.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Si1Yh1sb" Received: by mail-qv1-f42.google.com with SMTP id 6a1803df08f44-8ccf01ba514so16774276d6.0 for ; Fri, 05 Jun 2026 07:57:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780671433; x=1781276233; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=AUsTZdpMdXg+RyQBEedVH+xsX7MRbssqaPr3VOFVT94=; b=Si1Yh1sbQQqwUhBK6PGzmvSWwRBxhiTGRNlscZYWnGjUquNfEWXn5iRef1hC0ciShB qALB/a55UFl0Ka/hxH0T000HIGDgnbIGaIS1jBk6+xGYuX1i4aI9s2YOBs9B/Wmjd73s XOjfk/yovamwb0SSKqQROCW9pJhCa47/B5DWrZ/e4ORoLKmSjcKzY4jUuz968KMgSm3q gzjGwZkq+aifzRQcdrUBrcMD5feC8rKknrl1P6NhMW6brllqQ/l53VPiOm/KGLHLHq2g o4rYDzsTTY2QV0sgyCH7FbVLzmMsM3Jx3dyAtX2gC5fFzkouRXVRSsYrnPZrvJCpSqU3 S6ow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780671433; x=1781276233; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=AUsTZdpMdXg+RyQBEedVH+xsX7MRbssqaPr3VOFVT94=; b=JXl4eqsXIJmmYbANr0pX5tpZBpILWLOUDp89l1CRlbq2wmTkTxwP7M7gdnAu/c0tYF M1wJNx5/roZxWWGUbMK6MXFOac0OxoVLmTu1LWrGJmHvc2Cin6h7fWxXJ0B1OLFPrYzZ fCqgugDnIcdqvUP9cirv14aaoDp8ewPVXhcnQn2ZZHlz4he5+D+crAdBHyqDLqK2FBOG taZevDjTIFAEblByu766oKzlKFWvoV5x2g3ifF36By/g9KyUcaCr3Ap6mAPGZ3U0g06l 9NIPa06QP5SFrcuNGhgjMC3O3B+aNyTspkffIQoXIdAW0IfaLBefav7DiUT6Ld1NuTAV WjLQ== X-Forwarded-Encrypted: i=1; AFNElJ9XH/vwfncxvPFNscqh4BQifZqgPvuQcSKeU8ibWf+XmmBwboNDgXz1pD7n9kzCgxJk3k6K5+/7J2XjZH0=@vger.kernel.org X-Gm-Message-State: AOJu0Yzg4KzXz9E8MILBmJ3aRwolDALuWQnR0lzPadnEBqxGycBO+Vux FqGnq2phgvpPoefR5dPkzU2V7bZyXnUy1Dyqc5uES69VvEBMoQeui2q2 X-Gm-Gg: Acq92OHiPc+xIsW6+qwA603TE+3qq0CqPmf9rzW7E2+BdWzuOjf+XX4QaHypYslM17J iUM2eooypnuuoapVE7z2wEF32GBilsXSTBgdFdoPpnsvKFSW22gSCLbUOD8WVzhnUCg70QZZKAV JwpK1myAXuwNicsgoYHhOGEEQIS53Rbv2kko3GZgkTcQsgLuduHKn8bpRnf1BruA/tc884toIE/ YkNmSvp057i0+mo816tjp8PhpS2Ff5kso4HQE4jLjoCGoux5A+jgMAopMdrP9dwsU1z+Ib0B83e i6bW0fPC3NsjuA9lYxnRhH3BU6Z7UM/LsnEh01DRvcvnaoL9G0ruCQY0EA5q9EaHdhmGqhyHt3q WNBVd2c6VL96jWeT51BYxp54pRCOfENLCjb7b3qs6OcK/Qj/O/BssREGOpS8PhnkGbFpvfd62pf UJNCiMi/DKdlUCU3noGciuJW04Um9SA1+G3dxrDp6E9+NbHHWq2U4POcvZqp2cQEIhBZ3qptEgB hO8037e2wZzA53fcjhhUi5KVMDXFB9gN+U5 X-Received: by 2002:a05:622a:a08:b0:516:d943:175f with SMTP id d75a77b69052e-51795c3dea1mr54279761cf.52.1780671432688; Fri, 05 Jun 2026 07:57:12 -0700 (PDT) Received: from battery.lan (pool-138-88-31-60.washdc.fios.verizon.net. [138.88.31.60]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8ceccdca075sm85746046d6.20.2026.06.05.07.57.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 05 Jun 2026 07:57:11 -0700 (PDT) From: David Windsor To: bpf@vger.kernel.org, Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko Cc: Martin KaFai Lau , Eduard Zingerman , Kumar Kartikeya Dwivedi , Song Liu , Yonghong Song , Jiri Olsa , John Fastabend , Stanislav Fomichev , linux-kernel@vger.kernel.org, David Windsor Subject: [PATCH bpf-next] bpf: reject sleepable BPF_LSM_CGROUP programs at load time Date: Fri, 5 Jun 2026 10:57:07 -0400 Message-ID: <20260605145707.608579-1-dwindsor@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The cgroup shim runs under rcu_read_lock_dont_migrate(), so we should not attach any sleepable BPF programs there. Add support to the verifier to explicitly reject attempts to load sleepable BPF programs destined for LSM cgroup attachment. Without this, we get the following splat from a BPF_LSM_CGROUP program marked BPF_F_SLEEPABLE attached to file_open when it calls bpf_get_dentry_xattr(): BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1567 in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 34317, name: load preempt_count: 0, expected: 0 RCU nest depth: 2, expected: 0 Call Trace: down_read+0x76/0x480 ext4_xattr_get+0x11f/0x700 __vfs_getxattr+0xf0/0x150 bpf_get_dentry_xattr+0xbb/0xf0 bpf_prog_e76a298dac9218c6_test_open+0x6a/0x85 __cgroup_bpf_run_lsm_current+0x326/0x840 bpf_trampoline_6442534646+0x62/0x14d security_file_open+0x34/0x60 do_dentry_open+0x340/0x1260 vfs_open+0x7a/0x440 path_openat+0x1bac/0x30a0 libbpf provides a .s named section variant for every sleepable program type except lsm_cgroup, reflecting that per-cgroup LSM programs are intended to only run in a non-sleepable context. The above splat was obtained by bypassing libbpf by using bpf(2) directly. Fixes: 69fd337a975c ("bpf: per-cgroup lsm flavor") Signed-off-by: David Windsor --- kernel/bpf/verifier.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c index 8ed484cb1a8a..821654bcbaa7 100644 --- a/kernel/bpf/verifier.c +++ b/kernel/bpf/verifier.c @@ -19099,8 +19099,10 @@ static bool can_be_sleepable(struct bpf_prog *prog) return false; } } - return prog->type == BPF_PROG_TYPE_LSM || - prog->type == BPF_PROG_TYPE_KPROBE /* only for uprobes */ || + if (prog->type == BPF_PROG_TYPE_LSM) + return prog->expected_attach_type != BPF_LSM_CGROUP; + + return prog->type == BPF_PROG_TYPE_KPROBE /* only for uprobes */ || prog->type == BPF_PROG_TYPE_STRUCT_OPS || prog->type == BPF_PROG_TYPE_RAW_TRACEPOINT || prog->type == BPF_PROG_TYPE_TRACEPOINT; -- 2.53.0