From: Amery Hung <ameryhung@gmail.com>
To: bpf@vger.kernel.org
Cc: alexei.starovoitov@gmail.com, andrii@kernel.org,
daniel@iogearbox.net, eddyz87@gmail.com, memxor@gmail.com,
ameryhung@gmail.com, kernel-team@meta.com
Subject: [PATCH bpf-next v2 00/18] Generate bpf_func_proto for kfunc
Date: Fri, 24 Jul 2026 12:07:54 -0700 [thread overview]
Message-ID: <20260724190813.1458271-1-ameryhung@gmail.com> (raw)
Hi,
This is the second of three patch sets to unify kfunc and helper
argument verification. It:
1) further aligns the kfunc and helper argument checks,
2) makes kfunc argument type classification depend solely on BTF, and
3) generates a bpf_func_proto for each kfunc.
With classification now a pure function of the kfunc's BTF, it is computed
once at add-call time and cached in the generated bpf_func_proto, rather
than re-derived on every verification of the call. Along the way it also
fixes a few issues.
The next patch set will align the argument register compatibility checks
and route helper and kfunc argument verification through a single shared
function.
[1/3] https://lore.kernel.org/bpf/20260715064047.1793790-1-ameryhung@gmail.com/
Changelog
v1 -> v2:
- patch 2: use reg_arg_name() for the map-mismatch message; derive the
object register correctly on both helper and kfunc paths
- patch 3: reject non-CONST_PTR_TO_MAP regs (base_type check) to fix
map-value type confusion
- patch 15: also reject referenced regs with unsafe modifiers (e.g.
MEM_PERCPU)
- patch 17: reject non-SCALAR_VALUE for KF_ARG_MEM_SIZE
Amery Hung (18):
bpf: Drop process_timer_func wrappers
bpf: Unify const map ptr argument checking for helpers and kfuncs
bpf: Split kfunc map argument into __const_map and __map
bpf: Pass kfunc meta to mem and mem_size check
bpf: Check helper and kfunc mem+size arguments identically
selftests/bpf: Add tests for helper and kfunc mem+size arguments
bpf: Check fixed-size mem args of helpers and kfuncs the same way
bpf: Express ARG_CONST_SIZE_OR_ZERO as ARG_CONST_SIZE |
SCALAR_MAYBE_ZERO
bpf: Rename ARG_CONST_SIZE{,_OR_ZERO} to ARG_MEM_SIZE{,_OR_ZERO}
bpf: Fold __szk const size handling into the scalar arg path
bpf: Classify kfunc mem_size args from BTF without register state
bpf: Handle NULL kfunc pointer args without a KF_ARG_PTR_TO_NULL type
bpf: Distinguish fixed- and variable-size kfunc mem args with
MEM_FIXED_SIZE
bpf: Check helper mem+size in ARG_PTR_TO_MEM case
bpf: Classify kfunc pointer arguments from BTF, resolve type against
the register
bpf: Tag nullable kfunc pointer args with PTR_MAYBE_NULL
bpf: Classify scalar kfunc arguments from BTF
bpf: Generate kfunc argument prototype at add-call time
Documentation/bpf/kfuncs.rst | 30 +-
include/linux/bpf.h | 42 +-
include/linux/bpf_verifier.h | 31 +-
kernel/bpf/backtrack.c | 2 +-
kernel/bpf/bpf_lsm.c | 4 +-
kernel/bpf/btf.c | 2 +-
kernel/bpf/cgroup.c | 8 +-
kernel/bpf/core.c | 4 +-
kernel/bpf/helpers.c | 42 +-
kernel/bpf/ringbuf.c | 2 +-
kernel/bpf/stackmap.c | 10 +-
kernel/bpf/syscall.c | 6 +-
kernel/bpf/verifier.c | 786 ++++++++++--------
kernel/trace/bpf_trace.c | 62 +-
net/core/filter.c | 116 +--
.../selftests/bpf/prog_tests/verifier.c | 2 +
.../selftests/bpf/progs/cgrp_kfunc_failure.c | 2 +-
.../bpf/progs/mem_rdonly_untrusted.c | 2 +-
.../selftests/bpf/progs/task_kfunc_failure.c | 2 +-
.../selftests/bpf/progs/verifier_bounds.c | 2 +-
.../progs/verifier_helper_access_var_len.c | 6 +-
.../bpf/progs/verifier_helper_value_access.c | 2 +-
.../bpf/progs/verifier_mem_size_reg.c | 60 ++
.../selftests/bpf/progs/verifier_vfs_reject.c | 6 +-
tools/testing/selftests/bpf/verifier/calls.c | 6 +-
25 files changed, 711 insertions(+), 526 deletions(-)
create mode 100644 tools/testing/selftests/bpf/progs/verifier_mem_size_reg.c
--
2.52.0
next reply other threads:[~2026-07-24 19:08 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-24 19:07 Amery Hung [this message]
2026-07-24 19:07 ` [PATCH bpf-next v2 01/18] bpf: Drop process_timer_func wrappers Amery Hung
2026-07-25 1:39 ` Eduard Zingerman
2026-07-24 19:07 ` [PATCH bpf-next v2 02/18] bpf: Unify const map ptr argument checking for helpers and kfuncs Amery Hung
2026-07-24 19:28 ` sashiko-bot
2026-07-24 20:49 ` Amery Hung
2026-07-24 21:29 ` Kumar Kartikeya Dwivedi
2026-07-25 1:57 ` Eduard Zingerman
2026-07-24 19:07 ` [PATCH bpf-next v2 03/18] bpf: Split kfunc map argument into __const_map and __map Amery Hung
2026-07-24 19:07 ` [PATCH bpf-next v2 04/18] bpf: Pass kfunc meta to mem and mem_size check Amery Hung
2026-07-24 19:07 ` [PATCH bpf-next v2 05/18] bpf: Check helper and kfunc mem+size arguments identically Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 06/18] selftests/bpf: Add tests for helper and kfunc mem+size arguments Amery Hung
2026-07-24 19:25 ` sashiko-bot
2026-07-24 19:08 ` [PATCH bpf-next v2 07/18] bpf: Check fixed-size mem args of helpers and kfuncs the same way Amery Hung
2026-07-24 19:32 ` sashiko-bot
2026-07-24 20:39 ` Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 08/18] bpf: Express ARG_CONST_SIZE_OR_ZERO as ARG_CONST_SIZE | SCALAR_MAYBE_ZERO Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 09/18] bpf: Rename ARG_CONST_SIZE{,_OR_ZERO} to ARG_MEM_SIZE{,_OR_ZERO} Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 10/18] bpf: Fold __szk const size handling into the scalar arg path Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 11/18] bpf: Classify kfunc mem_size args from BTF without register state Amery Hung
2026-07-24 19:38 ` sashiko-bot
2026-07-24 22:52 ` Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 12/18] bpf: Handle NULL kfunc pointer args without a KF_ARG_PTR_TO_NULL type Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 13/18] bpf: Distinguish fixed- and variable-size kfunc mem args with MEM_FIXED_SIZE Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 14/18] bpf: Check helper mem+size in ARG_PTR_TO_MEM case Amery Hung
2026-07-24 19:47 ` sashiko-bot
2026-07-24 21:10 ` Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 15/18] bpf: Classify kfunc pointer arguments from BTF, resolve type against the register Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 16/18] bpf: Tag nullable kfunc pointer args with PTR_MAYBE_NULL Amery Hung
2026-07-24 19:38 ` sashiko-bot
2026-07-24 19:08 ` [PATCH bpf-next v2 17/18] bpf: Classify scalar kfunc arguments from BTF Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 18/18] bpf: Generate kfunc argument prototype at add-call time Amery Hung
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260724190813.1458271-1-ameryhung@gmail.com \
--to=ameryhung@gmail.com \
--cc=alexei.starovoitov@gmail.com \
--cc=andrii@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=kernel-team@meta.com \
--cc=memxor@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.