All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH bpf-next v3 00/18] Generate bpf_func_proto for kfunc
@ 2026-08-01  7:46 Amery Hung
  2026-08-01  7:46 ` [PATCH bpf-next v3 01/18] bpf: Drop process_timer_func wrappers Amery Hung
                   ` (17 more replies)
  0 siblings, 18 replies; 23+ messages in thread
From: Amery Hung @ 2026-08-01  7:46 UTC (permalink / raw)
  To: bpf
  Cc: alexei.starovoitov, andrii, daniel, eddyz87, memxor, ameryhung,
	kernel-team

Hi,

This is the second of three patch sets to unify kfunc and helper
argument verification. It:

  1) further aligns the kfunc and helper argument checks,
  2) makes kfunc argument type classification depend solely on BTF, and
  3) generates a bpf_func_proto for each kfunc.

With classification now a pure function of the kfunc's BTF, it is computed
once at add-call time and cached in the generated bpf_func_proto, rather
than re-derived on every verification of the call. Along the way it also
fixes a few issues.

The next patch set will align the argument register compatibility checks
and route helper and kfunc argument verification through a single shared
function.


[1/3] https://lore.kernel.org/bpf/20260715064047.1793790-1-ameryhung@gmail.com/


Changelog

v2 -> v3:
 - Drop a patch that introduces SCALAR_MAYBE_ZERO (Eduard)
 - Drop patch make helper handle mem+size at mem arg, and instead make
   kfunc also handle mem+size at size
 - patch 5: New patch replacing temporary mark_ptr_not_null_reg hack
   with refine_ptr_not_null_reg (Eduard)
 - patch 8: Only allow global subprog to read poisoned stack slots
   (Eduard)
 - patch 11: Test a precision gap when passing NULL to nullable-mem +
   size arg (Eduard)
 - patch 15: Reorganize BTF_ID, MEM, MEM+SIZE classification for
   clarity (Eduard)
 - patch 18: Emded bpf_func_proto in bpf_kfunc_desc and dynamically
   resize bpf_kfunc_desc_tab; Record saved_dst_prog_type early in
   bpf_prog_load to avoid introducing a fallback logic in
   resolve_prog_type (Eduard)

   Link: https://lore.kernel.org/bpf/20260724190813.1458271-1-ameryhung@gmail.com/

v1 -> v2:
 - patch 2: use reg_arg_name() for the map-mismatch message; derive the
   object register correctly on both helper and kfunc paths
 - patch 3: reject non-CONST_PTR_TO_MAP regs (base_type check) to fix
   map-value type confusion
 - patch 15: also reject referenced regs with unsafe modifiers (e.g.
   MEM_PERCPU)
 - patch 17: reject non-SCALAR_VALUE for KF_ARG_MEM_SIZE 


Amery Hung (17):
  bpf: Drop process_timer_func wrappers
  bpf: Unify const map ptr argument checking for helpers and kfuncs
  bpf: Split kfunc map argument into __const_map and __map
  bpf: Pass kfunc meta to mem and mem_size check
  bpf: Check helper and kfunc mem+size arguments identically
  selftests/bpf: Test map lookup result refinement
  bpf: Check fixed-size mem args of helpers and kfuncs the same way
  bpf: Rename ARG_CONST_SIZE{,_OR_ZERO} to ARG_MEM_SIZE{,_OR_ZERO}
  bpf: Fold __szk const size handling into the scalar arg path
  selftests/bpf: Test __szk precision with a NULL nullable buffer
  bpf: Classify kfunc mem_size args from BTF without register state
  bpf: Handle NULL kfunc pointer args without a KF_ARG_PTR_TO_NULL type
  bpf: Distinguish fixed- and variable-size kfunc mem args with
    MEM_FIXED_SIZE
  bpf: Classify kfunc pointer arguments from BTF, resolve type against
    the register
  bpf: Tag nullable kfunc pointer args with PTR_MAYBE_NULL
  bpf: Classify scalar kfunc arguments from BTF
  bpf: Generate kfunc argument prototype at add-call time

Eduard Zingerman (1):
  bpf: Resolve map lookup result type at lookup time

 Documentation/bpf/kfuncs.rst                  |  30 +-
 include/linux/bpf.h                           |  40 +-
 include/linux/bpf_verifier.h                  |  22 +-
 kernel/bpf/backtrack.c                        |   2 +-
 kernel/bpf/bpf_lsm.c                          |   4 +-
 kernel/bpf/btf.c                              |   2 +-
 kernel/bpf/cgroup.c                           |   8 +-
 kernel/bpf/helpers.c                          |  42 +-
 kernel/bpf/ringbuf.c                          |   2 +-
 kernel/bpf/stackmap.c                         |  10 +-
 kernel/bpf/syscall.c                          |   8 +-
 kernel/bpf/verifier.c                         | 830 ++++++++++--------
 kernel/trace/bpf_trace.c                      |  62 +-
 net/core/filter.c                             | 116 +--
 .../selftests/bpf/prog_tests/verifier.c       |   4 +
 .../selftests/bpf/progs/cgrp_kfunc_failure.c  |   2 +-
 .../testing/selftests/bpf/progs/dynptr_fail.c |   2 +-
 .../bpf/progs/mem_rdonly_untrusted.c          |   2 +-
 .../selftests/bpf/progs/task_kfunc_failure.c  |   2 +-
 .../selftests/bpf/progs/verifier_bounds.c     |   2 +-
 .../progs/verifier_helper_access_var_len.c    |   6 +-
 .../bpf/progs/verifier_helper_value_access.c  |   2 +-
 .../selftests/bpf/progs/verifier_map_in_map.c |   2 +-
 .../bpf/progs/verifier_map_lookup_refine.c    |  73 ++
 .../bpf/progs/verifier_mem_size_reg.c         |  28 +
 .../selftests/bpf/progs/verifier_vfs_reject.c |   6 +-
 tools/testing/selftests/bpf/verifier/calls.c  |   6 +-
 27 files changed, 766 insertions(+), 549 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/verifier_map_lookup_refine.c
 create mode 100644 tools/testing/selftests/bpf/progs/verifier_mem_size_reg.c

-- 
2.52.0


^ permalink raw reply	[flat|nested] 23+ messages in thread

end of thread, other threads:[~2026-08-01  8:22 UTC | newest]

Thread overview: 23+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-01  7:46 [PATCH bpf-next v3 00/18] Generate bpf_func_proto for kfunc Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 01/18] bpf: Drop process_timer_func wrappers Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 02/18] bpf: Unify const map ptr argument checking for helpers and kfuncs Amery Hung
2026-08-01  8:03   ` sashiko-bot
2026-08-01  7:46 ` [PATCH bpf-next v3 03/18] bpf: Split kfunc map argument into __const_map and __map Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 04/18] bpf: Pass kfunc meta to mem and mem_size check Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 05/18] bpf: Resolve map lookup result type at lookup time Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 06/18] bpf: Check helper and kfunc mem+size arguments identically Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 07/18] selftests/bpf: Test map lookup result refinement Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 08/18] bpf: Check fixed-size mem args of helpers and kfuncs the same way Amery Hung
2026-08-01  8:17   ` sashiko-bot
2026-08-01  7:46 ` [PATCH bpf-next v3 09/18] bpf: Rename ARG_CONST_SIZE{,_OR_ZERO} to ARG_MEM_SIZE{,_OR_ZERO} Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 10/18] bpf: Fold __szk const size handling into the scalar arg path Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 11/18] selftests/bpf: Test __szk precision with a NULL nullable buffer Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 12/18] bpf: Classify kfunc mem_size args from BTF without register state Amery Hung
2026-08-01  8:09   ` sashiko-bot
2026-08-01  7:46 ` [PATCH bpf-next v3 13/18] bpf: Handle NULL kfunc pointer args without a KF_ARG_PTR_TO_NULL type Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 14/18] bpf: Distinguish fixed- and variable-size kfunc mem args with MEM_FIXED_SIZE Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 15/18] bpf: Classify kfunc pointer arguments from BTF, resolve type against the register Amery Hung
2026-08-01  8:22   ` sashiko-bot
2026-08-01  7:46 ` [PATCH bpf-next v3 16/18] bpf: Tag nullable kfunc pointer args with PTR_MAYBE_NULL Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 17/18] bpf: Classify scalar kfunc arguments from BTF Amery Hung
2026-08-01  7:46 ` [PATCH bpf-next v3 18/18] bpf: Generate kfunc argument prototype at add-call time Amery Hung

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.