From: sashiko-bot@kernel.org
To: "Yonghong Song" <yonghong.song@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v5 08/11] bpf: Reject register-pair returns when the subprog BTF is unreliable
Date: Fri, 14 Aug 2026 03:02:39 +0000 [thread overview]
Message-ID: <20260814030240.5E9981F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260813200250.1996395-1-yonghong.song@linux.dev>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] push_callback_call() incorrectly passes helper arguments for BTF validation, tainting callback subprograms as unreliable.
--
--- Patch [8]: [PATCH bpf-next v5 08/11] bpf: Reject register-pair returns when the subprog BTF is unreliable ---
commit c1362d6d7ccc6806c96ffe9fc78804a2b8b6f1b9
Author: Yonghong Song <yonghong.song@linux.dev>
bpf: Reject register-pair returns when the subprog BTF is unreliable
This patch rejects return values larger than 8 bytes as soon as the
subprogram's BTF prototype is marked unreliable. It adds
subprog_ret_pair_unreliable() and uses it in check_func_call() to
prevent tracking R2 based on a discarded signature.
> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index b23be0fa95af4..0ffb3bed1649e 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
[ ... ]
> @@ -9527,6 +9544,12 @@ static int check_func_call(struct bpf_verifier_env *env, struct bpf_insn *insn,
> return 0;
> }
>
> + if (subprog_ret_pair_unreliable(env, subprog)) {
> + verbose(env, "Func#%d ('%s') returns >8 bytes, which requires reliable BTF\n",
> + subprog, subprog_name(env, subprog));
> + return -EINVAL;
> + }
[Severity: High]
This is a pre-existing issue, but will this new check incorrectly reject
valid BPF programs because of how push_callback_call() marks subprograms
as unreliable?
Looking at push_callback_call():
caller = state->frame[state->curframe];
err = btf_check_subprog_call(env, subprog, caller->regs);
It passes the caller's registers (which contain the helper arguments, e.g.,
the PTR_TO_FUNC for bpf_loop) instead of the actual arguments the callback
will receive. Because these arguments don't match the callback's prototype,
btf_check_subprog_call() fails, sets the unreliable flag to true on the
subprogram, and returns -EINVAL.
push_callback_call() ignores this error, leaving the callback permanently
tainted as unreliable.
If a callback subprogram returns >8 bytes, won't it be incorrectly rejected
here if it is also called directly elsewhere in the program, since the
unreliability flag was set mistakenly?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813200210.1991507-1-yonghong.song@linux.dev?part=8
next prev parent reply other threads:[~2026-08-14 3:02 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 20:02 [PATCH bpf-next v5 00/11] bpf: Support aggregate return values up to 16 bytes Yonghong Song
2026-08-13 20:02 ` [PATCH bpf-next v5 01/11] bpf: Factor check_global_ret_scalar_reg() out of the global return check Yonghong Song
2026-08-13 20:02 ` [PATCH bpf-next v5 02/11] bpf: Add helpers to describe the R0:R2 return register pair Yonghong Song
2026-08-13 21:11 ` bot+bpf-ci
2026-08-13 20:02 ` [PATCH bpf-next v5 03/11] bpf: Wire up JIT support for 16-byte kfunc returns Yonghong Song
2026-08-14 1:20 ` sashiko-bot
2026-08-13 20:02 ` [PATCH bpf-next v5 04/11] bpf: Track R2 of register-pair returns in precision backtracking Yonghong Song
2026-08-13 20:49 ` bot+bpf-ci
2026-08-13 20:02 ` [PATCH bpf-next v5 05/11] bpf: Account R2 of register-pair returns in live register analysis Yonghong Song
2026-08-14 1:50 ` sashiko-bot
2026-08-13 20:02 ` [PATCH bpf-next v5 06/11] bpf: Add verifier support for 16-byte returns in R0:R2 Yonghong Song
2026-08-13 21:11 ` bot+bpf-ci
2026-08-14 2:26 ` sashiko-bot
2026-08-13 20:02 ` [PATCH bpf-next v5 07/11] bpf: Enable aggregate return types up to 16 bytes Yonghong Song
2026-08-13 20:02 ` [PATCH bpf-next v5 08/11] bpf: Reject register-pair returns when the subprog BTF is unreliable Yonghong Song
2026-08-13 20:49 ` bot+bpf-ci
2026-08-14 3:02 ` sashiko-bot [this message]
2026-08-13 20:02 ` [PATCH bpf-next v5 09/11] selftests/bpf: Add C tests for 16-byte returns in R0:R2 Yonghong Song
2026-08-13 21:11 ` bot+bpf-ci
2026-08-13 20:03 ` [PATCH bpf-next v5 10/11] selftests/bpf: Add inline-asm and subprog tests for R0:R2 returns Yonghong Song
2026-08-13 21:11 ` bot+bpf-ci
2026-08-13 20:03 ` [PATCH bpf-next v5 11/11] Documentation/bpf: Document up to 16-byte kfunc return values in R0:R2 Yonghong Song
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814030240.5E9981F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.