All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Siddharth Chintamaneni" <sidchintamaneni@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v1 1/2] bpf: allow terminal gotox instructions
Date: Sun, 30 Aug 2026 07:45:07 +0000	[thread overview]
Message-ID: <20260830074507.876B11F00A3E@smtp.kernel.org> (raw)
In-Reply-To: <20260830073125.360934-1-sidchintamaneni@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] bpf_throw kfunc is incorrectly rejected as the last instruction of a subprogram.
--

commit 2856cb56c044a060705479701aa63316b773e7de
Author: Siddharth Chintamaneni <sidchintamaneni@gmail.com>

bpf: allow terminal gotox instructions

This commit skips direct-offset validation for gotox instructions in
check_subprogs() and accepts them as non-fallthrough terminal instructions.
The actual targets are validated during CFG construction instead.

> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index e036ae20bf6b9..44195ec1445d9 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
[ ... ]
> @@ -3106,7 +3108,8 @@ static int check_subprogs(struct bpf_verifier_env *env)
>  			 */
>  			if (code != (BPF_JMP | BPF_EXIT) &&
>  			    code != (BPF_JMP32 | BPF_JA) &&
> -			    code != (BPF_JMP | BPF_JA)) {
> +			    code != (BPF_JMP | BPF_JA) &&
> +			    !insn_is_gotox(&insn[i])) {

[Severity: High]
This isn't a bug introduced by this patch, but does check_subprogs()
incorrectly reject bpf_throw calls when they are used as terminal instructions?

The comment just above this block explicitly states that the last instruction
of the subprogram can be a bpf_throw call.

However, the if condition only allows exits, unconditional jumps, and
gotox instructions.

Because there is no check allowing bpf_throw (like checking if the call is a
throw kfunc), will a valid BPF program ending with a bpf_throw instruction be
incorrectly rejected during load when it hits this validation?

>  				verbose(env, "last insn is not an exit or jmp\n");
>  				bpf_diag_program_structure(
>  					env, i, "subprogram can fall through",

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260830073125.360934-1-sidchintamaneni@gmail.com?part=1

  parent reply	other threads:[~2026-08-30  7:45 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-30  7:31 [PATCH bpf-next v1 1/2] bpf: allow terminal gotox instructions Siddharth Chintamaneni
2026-08-30  7:31 ` [PATCH bpf-next v1 2/2] selftests/bpf: Add compiler-layout terminal gotox test Siddharth Chintamaneni
2026-08-31 12:34   ` Anton Protopopov
2026-08-30  7:45 ` sashiko-bot [this message]
2026-08-30  8:34 ` [PATCH bpf-next v1 1/2] bpf: allow terminal gotox instructions bot+bpf-ci
2026-08-31 12:21 ` Anton Protopopov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260830074507.876B11F00A3E@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sidchintamaneni@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.