From: sashiko-bot@kernel.org
To: chenyuan_fl@163.com
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf v2 2/2] selftests/bpf: Add regression test for queue/stack map size limit
Date: Mon, 10 Aug 2026 09:39:27 +0000 [thread overview]
Message-ID: <20260810093927.934E61F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260810092814.2698521-3-chenyuan_fl@163.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] Missing file descriptor cleanup on the test failure path for the first bpf_map_create call.
--
--- Patch [2]: [PATCH bpf v2 2/2] selftests/bpf: Add regression test for queue/stack map size limit ---
commit 25c3a9fe96d53115b495649d174f217a4729daca
Author: Yuan Chen <chenyuan@kylinos.cn>
selftests/bpf: Add regression test for queue/stack map size limit
This commit adds regression tests to ensure that queue and stack maps whose
element storage would overflow the u32 head/tail index multiplication or
wrap the u32 capacity counter are properly rejected at creation time.
> diff --git a/tools/testing/selftests/bpf/prog_tests/queue_stack_map.c b/tools/testing/selftests/bpf/prog_tests/queue_stack_map.c
> index 41441325e1794..8ab07ea777759 100644
> --- a/tools/testing/selftests/bpf/prog_tests/queue_stack_map.c
> +++ b/tools/testing/selftests/bpf/prog_tests/queue_stack_map.c
[ ... ]
> @@ -101,8 +101,53 @@ static void test_queue_stack_map_by_type(int type)
> bpf_object__close(obj);
> }
>
> +static void test_queue_stack_map_alloc_check(void)
> +{
> + LIBBPF_OPTS(bpf_map_create_opts, opts);
> + const __u32 big_value = 1 << 20; /* 1MB */
> + int fd, saved_errno;
> +
> + /*
> + * Regression test for the u32 index overflow in queue/stack maps:
> + * a map whose element storage (max_entries * value_size) exceeds
> + * U32_MAX bytes must be rejected at creation time, otherwise the
> + * u32 head/tail index multiplication wraps and push/peek/pop
> + * address the wrong element. 8192 * 1MB = 8GB > U32_MAX.
> + */
> + fd = bpf_map_create(BPF_MAP_TYPE_QUEUE, NULL, 0, big_value, 8192, &opts);
> + saved_errno = errno;
> + ASSERT_LT(fd, 0, "queue_oversize_fd");
> + ASSERT_EQ(saved_errno, E2BIG, "queue_oversize_errno");
[Severity: Low]
Should this test block include a close() call in case bpf_map_create()
unexpectedly succeeds?
If the kernel fails to reject the oversized map, fd will be a non-negative
value. Since ASSERT_LT logs the test failure but doesn't abort execution,
fd is overwritten in the very next bpf_map_create() call without being
cleaned up.
The subsequent tests in this function include a check to close the file
descriptor on the failure path:
> +
> + /*
> + * max_entries == U32_MAX would make the u32 capacity counter
> + * qs->size (max_entries + 1) wrap to 0, permanently breaking the
> + * map, so it must be rejected as well.
> + */
> + fd = bpf_map_create(BPF_MAP_TYPE_QUEUE, NULL, 0, 1, U32_MAX, &opts);
> + saved_errno = errno;
> + ASSERT_LT(fd, 0, "queue_u32max_fd");
> + ASSERT_EQ(saved_errno, E2BIG, "queue_u32max_errno");
> + if (fd >= 0)
> + close(fd);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260810092814.2698521-1-chenyuan_fl@163.com?part=2
next prev parent reply other threads:[~2026-08-10 9:39 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-10 9:28 [PATCH bpf v2 0/2] bpf: Fix queue/stack map u32 index overflow chenyuan_fl
2026-08-10 9:28 ` [PATCH bpf v2 1/2] " chenyuan_fl
2026-08-10 10:28 ` bot+bpf-ci
2026-08-10 9:28 ` [PATCH bpf v2 2/2] selftests/bpf: Add regression test for queue/stack map size limit chenyuan_fl
2026-08-10 9:39 ` sashiko-bot [this message]
2026-08-10 10:28 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810093927.934E61F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=chenyuan_fl@163.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.