* [PATCH] tools libbpf: Fix signed shift UB in btf_type_info()
@ 2026-09-03 8:26 liujing
2026-09-03 8:34 ` sashiko-bot
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: liujing @ 2026-09-03 8:26 UTC (permalink / raw)
To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko
Cc: Eduard Zingerman, Kumar Kartikeya Dwivedi, bpf, linux-kernel,
Liu Jing
From: Liu Jing <liujing@cmss.chinamobile.com>
In btf_type_info(), the expression `kflag << 31` performs a signed
integer shift. When kflag is 1, this sets the sign bit of a 32-bit
signed integer, which is undefined behavior in C.
Fix it by casting kflag to unsigned int before the shift.
Signed-off-by: Liu Jing <liujing@cmss.chinamobile.com>
---
--- a/tools/lib/bpf/libbpf_internal.h
+++ b/tools/lib/bpf/libbpf_internal.h
@@ -259,7 +259,7 @@
static inline __u32 btf_type_info(int kind, int vlen, int kflag)
{
- return (kflag << 31) | (kind << 24) | vlen;
+ return (((unsigned int)kflag << 31)) | (kind << 24) | vlen;
}
enum map_def_parts {
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] tools libbpf: Fix signed shift UB in btf_type_info()
2026-09-03 8:26 [PATCH] tools libbpf: Fix signed shift UB in btf_type_info() liujing
@ 2026-09-03 8:34 ` sashiko-bot
2026-09-03 9:05 ` bot+bpf-ci
2026-09-11 17:29 ` Andrii Nakryiko
2 siblings, 0 replies; 4+ messages in thread
From: sashiko-bot @ 2026-09-03 8:34 UTC (permalink / raw)
To: liujing; +Cc: bpf
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The commit provides an incomplete fix: it resolves the signed shift undefined behavior in the `btf_type_info()` function but misses the exact same undefined behavior in the `BTF_INFO_ENC()` macro defined in the same file (and duplicated in selftests).
--
commit d2829a28ec022a655878147a1269bec0aaf774db
Author: Liu Jing <liujing@cmss.chinamobile.com>
tools libbpf: Fix signed shift UB in btf_type_info()
This commit fixes a signed shift undefined behavior in btf_type_info() by
casting the kflag parameter to an unsigned int before left-shifting by 31
bits.
> diff --git a/tools/lib/bpf/libbpf_internal.h b/tools/lib/bpf/libbpf_internal.h
> index 4c46d34fc055d..2fda8c916cc35 100644
> --- a/tools/lib/bpf/libbpf_internal.h
> +++ b/tools/lib/bpf/libbpf_internal.h
> @@ -259,7 +259,7 @@ static inline enum btf_func_linkage btf_func_linkage(const struct btf_type *t)
>
> static inline __u32 btf_type_info(int kind, int vlen, int kflag)
> {
> - return (kflag << 31) | (kind << 24) | vlen;
> + return (((unsigned int)kflag << 31)) | (kind << 24) | vlen;
> }
[Severity: High]
This isn't a bug introduced by this patch, but while fixing the signed
shift undefined behavior in btf_type_info(), it looks like the exact
same issue was missed in the BTF_INFO_ENC() macro defined in this same
file.
The BTF_INFO_ENC() macro evaluates !!(kind_flag) << 31:
#define BTF_INFO_ENC(kind, kind_flag, vlen) \
((!!(kind_flag) << 31) | ((kind) << 24) | ((vlen) & BTF_MAX_VLEN))
Because !!(kind_flag) yields a signed 32-bit int, shifting it left by 31
bits results in 1 << 31 when kind_flag is non-zero (e.g., when encoding
BTF_KIND_DECL_TAG). Doesn't this also trigger the same undefined behavior
that compilers could exploit to generate corrupted BTF data?
Additionally, it looks like this same macro is duplicated in the selftests
under tools/testing/selftests/bpf/test_btf.h and
tools/testing/selftests/bpf/progs/syscall.c. Should those be updated as
well to ensure a complete fix across both libbpf and the selftests?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260903082616.5096-1-liujing@cmss.chinamobile.com?part=1
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] tools libbpf: Fix signed shift UB in btf_type_info()
2026-09-03 8:26 [PATCH] tools libbpf: Fix signed shift UB in btf_type_info() liujing
2026-09-03 8:34 ` sashiko-bot
@ 2026-09-03 9:05 ` bot+bpf-ci
2026-09-11 17:29 ` Andrii Nakryiko
2 siblings, 0 replies; 4+ messages in thread
From: bot+bpf-ci @ 2026-09-03 9:05 UTC (permalink / raw)
To: liujing, ast, daniel, andrii
Cc: eddyz87, memxor, bpf, linux-kernel, liujing, ast, andrii, daniel,
martin.lau, eddyz87, yonghong.song, mason, ihor.solodrai
[-- Attachment #1: Type: text/plain, Size: 1005 bytes --]
> In btf_type_info(), the expression `kflag << 31` performs a signed
> integer shift. When kflag is 1, this sets the sign bit of a 32-bit
> signed integer, which is undefined behavior in C.
>
> Fix it by casting kflag to unsigned int before the shift.
>
> Signed-off-by: Liu Jing <liujing@cmss.chinamobile.com>
This looks like a bug fix for undefined behavior that was introduced in
an earlier commit. Should this include a Fixes: tag?
The signed shift undefined behavior in btf_type_info() appears to have
been introduced by commit aea28a602fa1 ("libbpf: Mark BPF subprogs with
hidden visibility as static for BPF verifier"). Would it be appropriate
to add:
Fixes: aea28a602fa1 ("libbpf: Mark BPF subprogs with hidden visibility as static for BPF verifier")
---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
CI run summary: https://github.com/kernel-patches/bpf/actions/runs/33734678501
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] tools libbpf: Fix signed shift UB in btf_type_info()
2026-09-03 8:26 [PATCH] tools libbpf: Fix signed shift UB in btf_type_info() liujing
2026-09-03 8:34 ` sashiko-bot
2026-09-03 9:05 ` bot+bpf-ci
@ 2026-09-11 17:29 ` Andrii Nakryiko
2 siblings, 0 replies; 4+ messages in thread
From: Andrii Nakryiko @ 2026-09-11 17:29 UTC (permalink / raw)
To: liujing
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, bpf, linux-kernel
On Thu, Sep 3, 2026 at 1:26 AM liujing <liujing@cmss.chinamobile.com> wrote:
>
> From: Liu Jing <liujing@cmss.chinamobile.com>
>
> In btf_type_info(), the expression `kflag << 31` performs a signed
> integer shift. When kflag is 1, this sets the sign bit of a 32-bit
> signed integer, which is undefined behavior in C.
>
> Fix it by casting kflag to unsigned int before the shift.
>
> Signed-off-by: Liu Jing <liujing@cmss.chinamobile.com>
> ---
> --- a/tools/lib/bpf/libbpf_internal.h
> +++ b/tools/lib/bpf/libbpf_internal.h
> @@ -259,7 +259,7 @@
>
> static inline __u32 btf_type_info(int kind, int vlen, int kflag)
> {
> - return (kflag << 31) | (kind << 24) | vlen;
> + return (((unsigned int)kflag << 31)) | (kind << 24) | vlen;
this was recently fixed as part of slightly bigger set of fixes of the
similar kind
pw-bot: cr
> }
>
> enum map_def_parts {
>
>
>
>
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-11 17:30 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03 8:26 [PATCH] tools libbpf: Fix signed shift UB in btf_type_info() liujing
2026-09-03 8:34 ` sashiko-bot
2026-09-03 9:05 ` bot+bpf-ci
2026-09-11 17:29 ` Andrii Nakryiko
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.