All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Alexis Lothoré (eBPF Foundation)" <alexis.lothore@bootlin.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v6 9/9] selftests/bpf: add tests to validate KASAN on JIT programs
Date: Tue, 04 Aug 2026 18:35:39 +0000	[thread overview]
Message-ID: <20260804183540.464031F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260804-kasan-v6-9-549ef845f491@bootlin.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] BPF JIT KASAN instrumentation fails to save R10/R11 registers, corrupting BPF register state during atomic operations and memory probes.
- [High] BPF JIT emits KASAN checks for BPF_PROBE_MEM instructions, bypassing exception tables and causing log spam/DoS on expected invalid memory accesses.
--

--- Patch [9]: [PATCH bpf-next v6 9/9] selftests/bpf: add tests to validate KASAN on JIT programs ---
commit cb1fd6ebd1a7c30b4a1e50931fc142f072a09a37
Author: Alexis Lothoré (eBPF Foundation) <alexis.lothore@bootlin.com>

selftests/bpf: add tests to validate KASAN on JIT programs

Add a basic KASAN test runner that loads and test-run programs that can
trigger memory management bugs. The test captures kernel logs and ensure
that the expected KASAN splat is emitted. The runner covers different
cases and settings, including specialized tests for atomic ops.

> diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
> index 0b8b5dfe37ab0..b7881b9953107 100644
> --- a/arch/x86/net/bpf_jit_comp.c
> +++ b/arch/x86/net/bpf_jit_comp.c
> @@ -1110,6 +1121,92 @@ static void maybe_emit_1mod(u8 **pprog, u32 reg, bool is64)

[ ... ]

> +	/* Save r8 */
> +	EMIT2(0x41, 0x50);
> +	/* Save r9 */
> +	EMIT2(0x41, 0x51);
> +	/*
> +	 * SystemV ABI states that we should also save r10/r11, but in
> +	 * practice those registers are _not_ used by the limited set of
> +	 * kasan helpers we are calling here, so that's fine not to save those.
> +	 */

[Severity: High]
Is it safe to skip saving r10 and r11 here?

If the compiler allocates r10 in the KASAN helper, or if a KASAN report is
triggered calling kasan_report(), it appears r10 could be clobbered. This
could corrupt the BPF register state for operations that rely on BPF_REG_AX
(which maps to x86 r10).

> +
> +	/* mov rdi, addr_reg */
> +	EMIT_mov(BPF_REG_1, addr_reg);

[ ... ]

> @@ -2449,6 +2583,11 @@ static int do_jit(struct bpf_verifier_env *env, struct bpf_prog *bpf_prog, int *
>  				/* populate jmp_offset for JAE above to jump to start_of_ldx */
>  				start_of_ldx = prog;
>  				end_of_jmp[-1] = start_of_ldx - end_of_jmp;
> +			} else if (!accesses_stack_only) {
> +				err = emit_kasan_check(env, &prog, src_reg,
> +						       insn, ip, false);
> +				if (err)
> +					return err;
>  			}

[Severity: High]
Does this code emit KASAN checks for BPF_PROBE_MEM and BPF_PROBE_MEMSX
instructions?

Tracing programs frequently probe pointers that may be NULL or point to
userspace memory using BPF_PROBE_MEM. The verifier emits these
instructions to use the BPF exception table, which safely faults without
crashing or logging.

If emit_kasan_check() is called here unconditionally, it evaluates the
pointer using __asan_load*, which will call kasan_report() on NULL or
userspace pointers. Won't this bypass the exception table entirely and
print a KASAN BUG report to dmesg for every expected invalid pointer,
potentially causing log spam?

>  			if (BPF_MODE(insn->code) == BPF_PROBE_MEMSX ||
>  			    BPF_MODE(insn->code) == BPF_MEMSX)

[ ... ]

> @@ -2510,28 +2649,42 @@ static int do_jit(struct bpf_verifier_env *env, struct bpf_prog *bpf_prog, int *
>  			}
>  			fallthrough;
>  		case BPF_STX | BPF_ATOMIC | BPF_W:
> -		case BPF_STX | BPF_ATOMIC | BPF_DW:
> -			if (insn->imm == (BPF_AND | BPF_FETCH) ||
> -			    insn->imm == (BPF_OR | BPF_FETCH) ||
> -			    insn->imm == (BPF_XOR | BPF_FETCH)) {
> -				bool is64 = BPF_SIZE(insn->code) == BPF_DW;
> -				u32 real_src_reg = src_reg;
> -				u32 real_dst_reg = dst_reg;
> -				u8 *branch_target;
> -
> +		case BPF_STX | BPF_ATOMIC | BPF_DW: {
> +			bool is64 = BPF_SIZE(insn->code) == BPF_DW;
> +			u32 real_src_reg = src_reg;
> +			u32 real_dst_reg = dst_reg;
> +			u8 *branch_target;
> +			u8 *pprog;
> +			bool is_atomic_fetch =
> +				(insn->imm == (BPF_AND | BPF_FETCH) ||
> +				 insn->imm == (BPF_OR | BPF_FETCH) ||
> +				 insn->imm == (BPF_XOR | BPF_FETCH));
> +			if (is_atomic_fetch) {
>  				/*
>  				 * Can't be implemented with a single x86 insn.
>  				 * Need to do a CMPXCHG loop.
>  				 */
>  
>  				/* Will need RAX as a CMPXCHG operand so save R0 */
> +				pprog = prog;
>  				emit_mov_reg(&prog, true, BPF_REG_AX, BPF_REG_0);
>  				if (src_reg == BPF_REG_0)
>  					real_src_reg = BPF_REG_AX;
>  				if (dst_reg == BPF_REG_0)
>  					real_dst_reg = BPF_REG_AX;
> -
> +				ip += (prog - pprog);
> +			}
> +			if (!bpf_atomic_is_load_store(insn)) {
> +				if (!accesses_stack_only) {
> +					err = emit_kasan_check(env, &prog,
> +							       real_dst_reg,
> +							       insn, ip, true);
> +					if (err)
> +						return err;
> +				}

[Severity: High]
Could this call to emit_kasan_check() corrupt the BPF register state?

Just above, BPF_REG_0 is saved into BPF_REG_AX, which is mapped to x86 r10.
Since emit_kasan_check() explicitly skips saving r10, any clobbering of
r10 by the KASAN helpers will silently corrupt the saved value of BPF_REG_0.

>  				branch_target = prog;
> +			}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260804-kasan-v6-0-549ef845f491@bootlin.com?part=9

  reply	other threads:[~2026-08-04 18:35 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-04 17:45 [PATCH bpf-next v6 0/9] bpf: add support for KASAN checks in JITed programs Alexis Lothoré (eBPF Foundation)
2026-08-04 17:45 ` [PATCH bpf-next v6 1/9] bpf: mark instructions accessing program stack Alexis Lothoré (eBPF Foundation)
2026-08-04 17:45 ` [PATCH bpf-next v6 2/9] bpf: add BPF_JIT_KASAN for KASAN instrumentation of JITed programs Alexis Lothoré (eBPF Foundation)
2026-08-04 17:45 ` [PATCH bpf-next v6 3/9] bpf, x86: refactor BPF_ST management in do_jit Alexis Lothoré (eBPF Foundation)
2026-08-04 19:04   ` bot+bpf-ci
2026-08-04 17:45 ` [PATCH bpf-next v6 4/9] bpf, x86: emit KASAN checks in x86 JITed programs Alexis Lothoré (eBPF Foundation)
2026-08-04 18:10   ` sashiko-bot
2026-08-04 17:45 ` [PATCH bpf-next v6 5/9] bpf, x86: enable KASAN for JITed programs on x86 Alexis Lothoré (eBPF Foundation)
2026-08-04 18:10   ` sashiko-bot
2026-08-04 17:45 ` [PATCH bpf-next v6 6/9] selftests/bpf: make cmdline_contains stricter Alexis Lothoré (eBPF Foundation)
2026-08-04 18:49   ` bot+bpf-ci
2026-08-04 17:45 ` [PATCH bpf-next v6 7/9] selftests/bpf: add helpers for KASAN in JIT testing Alexis Lothoré (eBPF Foundation)
2026-08-04 17:45 ` [PATCH bpf-next v6 8/9] selftests/bpf: move bpf_jit_harden helper into testing_helpers Alexis Lothoré (eBPF Foundation)
2026-08-04 17:45 ` [PATCH bpf-next v6 9/9] selftests/bpf: add tests to validate KASAN on JIT programs Alexis Lothoré (eBPF Foundation)
2026-08-04 18:35   ` sashiko-bot [this message]
2026-08-05  8:24     ` Alexis Lothoré

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260804183540.464031F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=alexis.lothore@bootlin.com \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.