From: sashiko-bot@kernel.org
To: "Ihor Solodrai" <ihor.solodrai@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test
Date: Wed, 05 Aug 2026 23:17:55 +0000 [thread overview]
Message-ID: <20260805231755.966CC1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260805230648.2354989-4-ihor.solodrai@linux.dev>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Missing NULL pointer check on the result of `btf__type_by_id()` causes a segmentation fault when a kfunc symbol is missing.
--
--- Patch [3]: [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test ---
commit 833ac8bbb8ac1055e25790da1396864987e31541
Author: Ihor Solodrai <ihor.solodrai@linux.dev>
selftests/bpf: Verify arena type tags in resolve_btfids test
This commit extends test_resolve_btfids() to assert that resolve_btfids
emits the address_space(1) type attribute on the return type and arguments
of kfuncs marked with KF_ARENA_RET, KF_ARENA_ARG1 or KF_ARENA_ARG2.
> diff --git a/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c b/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
> index ac51fd4548214..8482f00046d4c 100644
> --- a/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
> +++ b/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
[ ... ]
> @@ -227,6 +260,39 @@ void test_resolve_btfids(void)
> check_kfunc_set(&test_kfunc_set);
> check_kfunc_set(&test_kfunc_set_rev);
>
> + /*
> + * Check resolve_btfids wrapped exactly the arena-flagged return/args
> + * with the address_space(1) type attribute, and left other
> + * pointers/returns untouched.
> + */
> + for (i = 0; i < ARRAY_SIZE(kfunc_symbols); i++) {
> + const struct btf_type *fn, *proto;
> + const struct btf_param *params;
> + const char *name = kfunc_symbols[i].name;
> + u32 fl = kfunc_symbols[i].flags;
> + __u32 nr;
> +
> + fn = btf__type_by_id(btf, kfunc_symbols[i].id);
> + if (!ASSERT_TRUE(btf_is_func(fn), name))
> + continue;
[Severity: Medium]
Could this cause a segmentation fault if a kfunc symbol is missing?
If resolve_symbols() fails to find a kfunc in the parsed BTF file, the
symbol's id remains -1. When -1 is passed to btf__type_by_id(), it
returns NULL.
Since btf_is_func() unconditionally accesses the info member, passing a
NULL pointer to it would crash the test program before the ASSERT_TRUE
evaluates.
Should we check if fn is NULL before passing it to btf_is_func()?
> + proto = btf__type_by_id(btf, fn->type);
> + if (!ASSERT_TRUE(btf_is_func_proto(proto), name))
> + continue;
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260805230648.2354989-1-ihor.solodrai@linux.dev?part=3
next prev parent reply other threads:[~2026-08-05 23:17 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-05 23:06 [PATCH bpf-next v2 0/6] resolve_btfids: Implement BTF tags emission for kfuncs Ihor Solodrai
2026-08-05 23:06 ` [PATCH bpf-next v2 1/6] resolve_btfids: Deduplicate BTF after btf2btf transformations Ihor Solodrai
2026-08-06 19:05 ` Eduard Zingerman
2026-08-06 20:48 ` Ihor Solodrai
2026-08-06 20:52 ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 2/6] resolve_btfids: Process KF_ARENA_* flags in resolve_btfids Ihor Solodrai
2026-08-06 19:12 ` Eduard Zingerman
2026-08-06 21:02 ` Ihor Solodrai
2026-08-06 21:12 ` Eduard Zingerman
2026-08-06 21:16 ` Ihor Solodrai
2026-08-05 23:06 ` [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test Ihor Solodrai
2026-08-05 23:17 ` sashiko-bot [this message]
2026-08-06 21:09 ` Ihor Solodrai
2026-08-06 19:15 ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 4/6] resolve_btfids: Emit bpf_kfunc and bpf_fastcall decl tags Ihor Solodrai
2026-08-06 19:18 ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 5/6] selftests/bpf: Verify decl tags emission in resolve_btfids test Ihor Solodrai
2026-08-06 19:20 ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 6/6] docs, resolve_btfids: Document kfunc BTF annotation emission Ihor Solodrai
2026-08-05 23:16 ` sashiko-bot
2026-08-06 21:12 ` Ihor Solodrai
2026-08-06 0:01 ` bot+bpf-ci
2026-08-06 21:13 ` Ihor Solodrai
2026-08-06 19:47 ` Eduard Zingerman
2026-08-06 21:06 ` Ihor Solodrai
2026-08-06 21:17 ` Eduard Zingerman
2026-08-06 21:19 ` Ihor Solodrai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260805231755.966CC1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=ihor.solodrai@linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.