All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH bpf v2 0/2] bpf: Preserve escaped dynptr slice ancestry
@ 2026-09-10  4:40 Xu Yunxiang
  2026-09-10  4:40 ` [PATCH bpf v2 1/2] bpf: Preserve escaped dynptr slice ancestry on subprog return Xu Yunxiang
  2026-09-10  4:40 ` [PATCH bpf v2 2/2] selftests/bpf: Test dynptr slices escaping a call frame Xu Yunxiang
  0 siblings, 2 replies; 6+ messages in thread
From: Xu Yunxiang @ 2026-09-10  4:40 UTC (permalink / raw)
  To: bpf
  Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Eduard Zingerman, Kumar Kartikeya Dwivedi, Amery Hung, Sashiko

Sashiko reported a verifier lifetime gap for a dynptr slice derived from a
clone in a subprogram. The slice can escape into its caller before the
subprogram returns. Once the clone's frame is gone, the slice still names
the clone id as its parent, but that graph node no longer exists. Releasing
the original dynptr therefore fails to reach the escaped slice, and the
verifier permits a subsequent access to the released ring buffer
reservation.

The same disconnect affects a dynptr constructed from another referenced
object. In particular, an skb dynptr created from a referenced qdisc skb
has the skb reference as its parent even though the skb dynptr type does
not own a reference itself.

Patch 1 reparents surviving slices from every callee-local dynptr that has
a tracked parent before the callee frame is freed. Patch 2 tests both the
ring buffer clone case and an skb slice returned from a subprogram and used
after the qdisc skb is released.

On the exact unpatched base, the new ring buffer stale-access test and the
qdisc stale-access test both loaded. The v1 fix rejected the ring buffer
case, but still allowed the qdisc case. With v2, both stale accesses are
rejected and the legal ring buffer control still loads.

The checks require CAP_BPF. This series is submitted as a verifier
correctness fix.

Please queue the verifier fix for stable after it reaches the BPF tree.

Tests:
  - W=1 make O=<build> kernel/bpf/verifier.o
  - make O=<build> -j12 bzImage modules
  - test_progs -t dynptr -v --workers=1
    (Summary: 2/134 PASSED, 0 SKIPPED, 0/0 FAILED)
  - test_progs -t ns_bpf_qdisc/invalid_dynptr_returned_slice -v
    --workers=1
    (Summary: 1/1 PASSED, 0 SKIPPED, 0/0 FAILED)
  - baseline/v1/v2 differential checks for the ring buffer and qdisc cases

The full unfiltered BPF selftest suite was not run.

Changes in v2:
  - Reparent slices from any dynptr with a tracked parent, covering skb
    dynptrs constructed from referenced qdisc skbs.
  - Add a qdisc regression test for a returned slice used after skb
    release.
  - Fix the selftest comment style and mark the expected failing access.

v1: https://lore.kernel.org/r/20260909042858.1734125-1-xyx2021@mail.ustc.edu.cn

Xu Yunxiang (2):
  bpf: Preserve escaped dynptr slice ancestry on subprog return
  selftests/bpf: Test dynptr slices escaping a call frame

 kernel/bpf/verifier.c                         | 34 +++++++++
 .../selftests/bpf/prog_tests/bpf_qdisc.c      |  2 +
 ...disc_fail__invalid_dynptr_returned_slice.c | 76 +++++++++++++++++++
 .../testing/selftests/bpf/progs/dynptr_fail.c | 49 ++++++++++++
 4 files changed, 161 insertions(+)
 create mode 100644 tools/testing/selftests/bpf/progs/bpf_qdisc_fail__invalid_dynptr_returned_slice.c


base-commit: 15e2565f1c43771af0bc5324971cabaad79ac286
-- 
2.43.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-10 17:23 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-10  4:40 [PATCH bpf v2 0/2] bpf: Preserve escaped dynptr slice ancestry Xu Yunxiang
2026-09-10  4:40 ` [PATCH bpf v2 1/2] bpf: Preserve escaped dynptr slice ancestry on subprog return Xu Yunxiang
2026-09-10  5:01   ` sashiko-bot
2026-09-10  8:07     ` Xu Yunxiang
2026-09-10 17:22   ` Amery Hung
2026-09-10  4:40 ` [PATCH bpf v2 2/2] selftests/bpf: Test dynptr slices escaping a call frame Xu Yunxiang

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.