From: Yonghong Song <yonghong.song@linux.dev>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
kernel-team@fb.com
Subject: [PATCH bpf-next v7 20/22] selftests/bpf: Add __set_global() and __ret_global() test tags
Date: Mon, 28 Sep 2026 17:17:46 -0700 [thread overview]
Message-ID: <20260929001746.3256138-1-yonghong.song@linux.dev> (raw)
In-Reply-To: <20260929001601.3242665-1-yonghong.song@linux.dev>
A test that has to look at a program's state after it ran needs a driver of
its own: open and load a skeleton, set an input, call
bpf_prog_test_run_opts(), read a variable back, destroy the skeleton. The
loader already does all of that for __retval(), and the only thing missing
is reaching the program's globals.
__set_global(var, value) writes one before the run and __ret_global(var,
value) checks one after it, both of them implying the execution __retval()
asks for. Either may be given more than once, for a test with more than
one input or more than one thing to look at afterwards; past
MAX_GLOBAL_VARS a tag is refused rather than quietly replacing the one
before it.
The variable is found the way veristat finds one: the map whose name ends
in ".bss" or ".data", the datasec of that name in the object's BTF, then
the variable within it. Those are two lookups that nothing so far has made
agree on a size, so where the variable lands is checked against the map it
was found beside. Four and eight byte variables are supported, which is
what a counter or a bitmask needs; anything else is refused rather than
read at the wrong width.
A value is held to the range its variable can represent, signedness taken
from the BTF the way veristat's set_global_var() does, and narrowed to
what is stored. Both tags use the one rule, so a negative literal means
the same to each: without it __ret_global(err, -22) on an int could never
match, the tag parsing 64 bits while the read gave back 32. Unlike
veristat this takes no enum names and runs native-endian only.
The value may be a '|' separated list of terms, so that a bitmask reads in
the test the way it is written in the program.
Suggested-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Yonghong Song <yonghong.song@linux.dev>
---
tools/testing/selftests/bpf/progs/bpf_misc.h | 7 +
tools/testing/selftests/bpf/test_loader.c | 314 ++++++++++++++++++-
2 files changed, 320 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/bpf/progs/bpf_misc.h b/tools/testing/selftests/bpf/progs/bpf_misc.h
index f3dbc3b59bff..9afa163fac5a 100644
--- a/tools/testing/selftests/bpf/progs/bpf_misc.h
+++ b/tools/testing/selftests/bpf/progs/bpf_misc.h
@@ -93,6 +93,11 @@
* __failure Expect program load failure in privileged mode.
* __failure_unpriv Expect program load failure in unprivileged mode.
*
+ * __set_global Set a global variable of the program to a value before
+ * executing it.
+ * __ret_global Execute the program and check that a global variable
+ * holds the given value afterwards. The variable has to
+ * live in .bss or .data and be four or eight bytes wide.
* __retval Execute the program using BPF_PROG_TEST_RUN command,
* expect return value to match passed parameter:
* - a decimal number
@@ -160,6 +165,8 @@
#define __log_level(lvl) __test_tag("test_log_level=" #lvl)
#define __flag(flag) __test_tag("test_prog_flags=" #flag)
#define __retval(val) __test_tag("test_retval=" XSTR(val))
+#define __set_global(var, val) __test_tag("test_global_set=" #var ":" XSTR(val))
+#define __ret_global(var, val) __test_tag("test_global_ret=" #var ":" XSTR(val))
#define __retval_unpriv(val) __test_tag("test_retval_unpriv=" XSTR(val))
#define __auxiliary __test_tag("test_auxiliary")
#define __auxiliary_unpriv __test_tag("test_auxiliary_unpriv")
diff --git a/tools/testing/selftests/bpf/test_loader.c b/tools/testing/selftests/bpf/test_loader.c
index 25eeb1c1248b..2492841f7a49 100644
--- a/tools/testing/selftests/bpf/test_loader.c
+++ b/tools/testing/selftests/bpf/test_loader.c
@@ -50,6 +50,13 @@ enum stack_mode {
SMALL_STACK = 1 << 1,
};
+#define MAX_GLOBAL_VARS 8
+
+struct global_var {
+ char *name;
+ __u64 val;
+};
+
struct test_subspec {
char *name;
char *description;
@@ -62,6 +69,10 @@ struct test_subspec {
int retval;
bool execute;
__u64 caps;
+ struct global_var set_globals[MAX_GLOBAL_VARS];
+ int set_global_cnt;
+ struct global_var ret_globals[MAX_GLOBAL_VARS];
+ int ret_global_cnt;
};
struct test_spec {
@@ -115,6 +126,34 @@ void free_msgs(struct expected_msgs *msgs)
msgs->cnt = 0;
}
+static void free_global_vars(struct global_var *vars, int *cnt)
+{
+ int i;
+
+ for (i = 0; i < *cnt; i++) {
+ free(vars[i].name);
+ vars[i].name = NULL;
+ }
+ *cnt = 0;
+}
+
+static int clone_global_vars(struct global_var *dst, int *dst_cnt,
+ const struct global_var *src, int src_cnt)
+{
+ int i;
+
+ for (i = 0; i < src_cnt; i++) {
+ dst[i].name = strdup(src[i].name);
+ if (!dst[i].name) {
+ free_global_vars(dst, dst_cnt);
+ return -ENOMEM;
+ }
+ dst[i].val = src[i].val;
+ (*dst_cnt)++;
+ }
+ return 0;
+}
+
static void free_test_spec(struct test_spec *spec)
{
/* Deallocate expect_msgs arrays. */
@@ -129,6 +168,11 @@ static void free_test_spec(struct test_spec *spec)
free_msgs(&spec->unpriv.stdout);
free_msgs(&spec->priv.stdout);
+ free_global_vars(spec->priv.set_globals, &spec->priv.set_global_cnt);
+ free_global_vars(spec->priv.ret_globals, &spec->priv.ret_global_cnt);
+ free_global_vars(spec->unpriv.set_globals, &spec->unpriv.set_global_cnt);
+ free_global_vars(spec->unpriv.ret_globals, &spec->unpriv.ret_global_cnt);
+
free(spec->priv.name);
free(spec->priv.description);
free(spec->unpriv.name);
@@ -311,6 +355,216 @@ static int parse_caps(const char *str, __u64 *val, const char *name)
return 0;
}
+static int parse_global_var(const char *str, struct global_var *vars, int *cnt,
+ const char *name)
+{
+ const char *colon = strrchr(str, ':');
+ struct global_var *var;
+ char *end;
+ __u64 *val;
+
+ if (!colon || colon == str) {
+ PRINT_FAIL("expecting '<variable>:<value>' for %s, got '%s'\n", name, str);
+ return -EINVAL;
+ }
+ if (*cnt >= MAX_GLOBAL_VARS) {
+ PRINT_FAIL("too many %s tags, at most %d are supported\n",
+ name, MAX_GLOBAL_VARS);
+ return -E2BIG;
+ }
+
+ var = &vars[*cnt];
+ val = &var->val;
+ *val = 0;
+ for (const char *term = colon + 1;;) {
+ __u64 v;
+
+ errno = 0;
+ v = strtoull(term, &end, 0);
+ if (errno || end == term) {
+ PRINT_FAIL("failed to parse %s value '%s'\n", name, colon + 1);
+ return -EINVAL;
+ }
+ *val |= v;
+ while (*end == ' ')
+ end++;
+ if (!*end)
+ break;
+ if (*end != '|') {
+ PRINT_FAIL("failed to parse %s value '%s'\n", name, colon + 1);
+ return -EINVAL;
+ }
+ term = end + 1;
+ }
+
+ var->name = strndup(str, colon - str);
+ if (!var->name) {
+ PRINT_FAIL("failed to allocate %s variable name\n", name);
+ return -ENOMEM;
+ }
+ (*cnt)++;
+
+ return 0;
+}
+
+/* As veristat's is_signed_type(): anything not plainly unsigned is signed. */
+static bool global_var_is_signed(const struct btf_type *t)
+{
+ if (btf_is_int(t))
+ return btf_int_encoding(t) & BTF_INT_SIGNED;
+ if (btf_is_any_enum(t))
+ return btf_kflag(t);
+ return true;
+}
+
+static int find_global_var(struct bpf_object *obj, const char *name,
+ struct bpf_map **map, __u32 *off, __u32 *sz,
+ bool *is_signed)
+{
+ static const char * const secs[] = { ".bss", ".data" };
+ struct btf *btf = bpf_object__btf(obj);
+ int i, s;
+ __u32 vsz;
+
+ if (!btf) {
+ PRINT_FAIL("no BTF for object\n");
+ return -ENOENT;
+ }
+
+ for (s = 0; s < ARRAY_SIZE(secs); s++) {
+ const struct btf_type *sec, *vt;
+ const struct btf_var_secinfo *vsi;
+ struct bpf_map *m = NULL, *iter;
+ size_t slen = strlen(secs[s]);
+ int id;
+
+ bpf_object__for_each_map(iter, obj) {
+ const char *mname = bpf_map__name(iter);
+ size_t len = mname ? strlen(mname) : 0;
+
+ if (len >= slen && strcmp(mname + len - slen, secs[s]) == 0) {
+ m = iter;
+ break;
+ }
+ }
+ id = btf__find_by_name_kind(btf, secs[s], BTF_KIND_DATASEC);
+ if (!m || id < 0)
+ continue;
+
+ sec = btf__type_by_id(btf, id);
+ vsi = btf_var_secinfos(sec);
+ for (i = 0; i < btf_vlen(sec); i++, vsi++) {
+ const struct btf_type *var = btf__type_by_id(btf, vsi->type);
+
+ if (strcmp(btf__name_by_offset(btf, var->name_off), name))
+ continue;
+ if (vsi->size != 4 && vsi->size != 8) {
+ PRINT_FAIL("'%s' is %u bytes, only 4 and 8 are supported\n",
+ name, vsi->size);
+ return -EINVAL;
+ }
+ vt = btf__type_by_id(btf, btf__resolve_type(btf, var->type));
+ if (!vt || !(btf_is_int(vt) || btf_is_any_enum(vt))) {
+ PRINT_FAIL("'%s' is not an int or an enum\n", name);
+ return -EINVAL;
+ }
+ *is_signed = global_var_is_signed(vt);
+ /*
+ * The map is found by the suffix of its name and the
+ * section by its own, so nothing so far has made the
+ * two agree on a size.
+ */
+ vsz = bpf_map__value_size(m);
+ if (vsi->offset > vsz || vsi->size > vsz - vsi->offset) {
+ PRINT_FAIL("'%s' at %u+%u is outside '%s' of %u bytes\n",
+ name, vsi->offset, vsi->size,
+ bpf_map__name(m), vsz);
+ return -EINVAL;
+ }
+ *map = m;
+ *off = vsi->offset;
+ *sz = vsi->size;
+ return 0;
+ }
+ }
+
+ PRINT_FAIL("no global variable '%s'\n", name);
+ return -ENOENT;
+}
+
+/*
+ * A tag's value is parsed as 64 bits, but the variable may be narrower and
+ * may be signed. Hold it to the range the variable can represent, the way
+ * veristat's set_global_var() does, and narrow it to what is stored.
+ */
+static int fit_global_var(const char *name, __u32 sz, bool is_signed, __u64 *val)
+{
+ long long v = (long long)*val;
+ long long max_val;
+ __u32 bits;
+
+ if (sz >= sizeof(*val))
+ return 0;
+ bits = sz * 8 - (is_signed ? 1 : 0);
+ max_val = 1ll << bits;
+ if (v >= max_val || v < (is_signed ? -max_val : 0)) {
+ PRINT_FAIL("value %lld for '%s' is out of range [%lld; %lld]\n",
+ v, name, is_signed ? -max_val : 0, max_val - 1);
+ return -EINVAL;
+ }
+ *val = (__u32)*val;
+ return 0;
+}
+
+static int access_global_var(struct bpf_object *obj, const char *name,
+ __u64 *val, __u32 *sz_out, bool *signed_out, bool set)
+{
+ __u32 off, sz, zero = 0;
+ bool is_signed;
+ struct bpf_map *map;
+ size_t vsz;
+ void *buf;
+ int err;
+
+ err = find_global_var(obj, name, &map, &off, &sz, &is_signed);
+ if (err)
+ return err;
+ if (sz_out)
+ *sz_out = sz;
+ if (signed_out)
+ *signed_out = is_signed;
+ if (set) {
+ err = fit_global_var(name, sz, is_signed, val);
+ if (err)
+ return err;
+ }
+
+ vsz = bpf_map__value_size(map);
+ buf = calloc(1, vsz);
+ if (!buf)
+ return -ENOMEM;
+
+ err = bpf_map__lookup_elem(map, &zero, sizeof(zero), buf, vsz, 0);
+ if (err) {
+ PRINT_FAIL("failed to read '%s': %d\n", name, err);
+ goto out;
+ }
+ if (!set) {
+ *val = sz == 4 ? *(__u32 *)(buf + off) : *(__u64 *)(buf + off);
+ goto out;
+ }
+ if (sz == 4)
+ *(__u32 *)(buf + off) = *val;
+ else
+ *(__u64 *)(buf + off) = *val;
+ err = bpf_map__update_elem(map, &zero, sizeof(zero), buf, vsz, 0);
+ if (err)
+ PRINT_FAIL("failed to write '%s': %d\n", name, err);
+out:
+ free(buf);
+ return err;
+}
+
static int parse_retval(const char *str, int *val, const char *name)
{
/*
@@ -557,6 +811,22 @@ static int parse_test_spec(struct test_loader *tester,
spec->mode_mask |= UNPRIV;
spec->unpriv.execute = true;
has_unpriv_retval = true;
+ } else if ((val = str_has_pfx(s, "test_global_set="))) {
+ err = parse_global_var(val, spec->priv.set_globals,
+ &spec->priv.set_global_cnt,
+ "__set_global");
+ if (err)
+ goto cleanup;
+ spec->priv.execute = true;
+ spec->mode_mask |= PRIV;
+ } else if ((val = str_has_pfx(s, "test_global_ret="))) {
+ err = parse_global_var(val, spec->priv.ret_globals,
+ &spec->priv.ret_global_cnt,
+ "__ret_global");
+ if (err)
+ goto cleanup;
+ spec->priv.execute = true;
+ spec->mode_mask |= PRIV;
} else if ((val = str_has_pfx(s, "test_log_level="))) {
err = parse_int(val, &spec->log_level, "test log level");
if (err)
@@ -742,6 +1012,23 @@ static int parse_test_spec(struct test_loader *tester,
spec->unpriv.execute = spec->priv.execute;
}
+ if (spec->priv.set_global_cnt && !spec->unpriv.set_global_cnt) {
+ err = clone_global_vars(spec->unpriv.set_globals,
+ &spec->unpriv.set_global_cnt,
+ spec->priv.set_globals,
+ spec->priv.set_global_cnt);
+ if (err)
+ goto cleanup;
+ }
+ if (spec->priv.ret_global_cnt && !spec->unpriv.ret_global_cnt) {
+ err = clone_global_vars(spec->unpriv.ret_globals,
+ &spec->unpriv.ret_global_cnt,
+ spec->priv.ret_globals,
+ spec->priv.ret_global_cnt);
+ if (err)
+ goto cleanup;
+ }
+
if (spec->unpriv.expect_msgs.cnt == 0)
clone_msgs(&spec->priv.expect_msgs, &spec->unpriv.expect_msgs);
if (spec->unpriv.expect_xlated.cnt == 0)
@@ -1356,7 +1643,7 @@ void run_subtest(struct test_loader *tester,
struct cap_state caps = {};
struct bpf_object *tobj;
struct bpf_map *map;
- int retval, err, i;
+ int retval, err, i, gi;
int links_cnt = 0;
bool should_load;
@@ -1532,6 +1819,14 @@ void run_subtest(struct test_loader *tester,
}
}
+ for (gi = 0; gi < subspec->set_global_cnt; gi++) {
+ __u64 v = subspec->set_globals[gi].val;
+
+ if (access_global_var(tobj, subspec->set_globals[gi].name,
+ &v, NULL, NULL, true))
+ goto tobj_cleanup;
+ }
+
err = do_prog_test_run(bpf_program__fd(tprog), &retval,
bpf_program__type(tprog) == BPF_PROG_TYPE_SYSCALL ? true : false,
spec->linear_sz);
@@ -1540,6 +1835,23 @@ void run_subtest(struct test_loader *tester,
goto tobj_cleanup;
}
+ for (gi = 0; gi < subspec->ret_global_cnt; gi++) {
+ __u64 want = subspec->ret_globals[gi].val, v = 0;
+ bool is_signed = false;
+ __u32 sz = 0;
+
+ if (access_global_var(tobj, subspec->ret_globals[gi].name, &v,
+ &sz, &is_signed, false))
+ goto tobj_cleanup;
+ if (fit_global_var(subspec->ret_globals[gi].name, sz, is_signed, &want))
+ goto tobj_cleanup;
+ if (v != want) {
+ PRINT_FAIL("Unexpected %s: 0x%llx != 0x%llx\n",
+ subspec->ret_globals[gi].name, v, want);
+ goto tobj_cleanup;
+ }
+ }
+
verify_stderr(bpf_program__fd(tprog), &subspec->stderr);
if (subspec->stdout.cnt) {
--
2.53.0-Meta
next prev parent reply other threads:[~2026-09-29 0:17 UTC|newest]
Thread overview: 46+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 0:16 [PATCH bpf-next v7 00/22] bpf: Run exception cleanup landing pads when bpf_unwind() unwinds Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 01/22] bpf: Pack bpf_insn_aux_data flags into bit fields Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 02/22] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 03/22] bpf: Add the bpf_unwind() and bpf_unwind_resume() kfuncs Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 04/22] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-29 0:33 ` sashiko-bot
2026-09-29 21:58 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 05/22] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-29 0:31 ` sashiko-bot
2026-09-29 22:04 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 06/22] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 07/22] bpf: Resume a covered call at its landing pad Yonghong Song
2026-09-29 0:31 ` sashiko-bot
2026-09-30 0:28 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 08/22] bpf: Require an unwind to leave a frame holding what it entered with Yonghong Song
2026-09-29 0:36 ` sashiko-bot
2026-09-30 1:09 ` Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 1:10 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 09/22] bpf: Refuse a landing pad that does not resume Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 10/22] bpf: Refuse a private stack for a program that can unwind Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 11/22] bpf: Dispatch cleanup pads by rewriting return addresses Yonghong Song
2026-09-29 1:14 ` bot+bpf-ci
2026-09-30 1:18 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 12/22] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-29 0:30 ` sashiko-bot
2026-09-30 1:34 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 13/22] bpf, arm64: " Yonghong Song
2026-09-29 1:14 ` bot+bpf-ci
2026-09-29 0:17 ` [PATCH bpf-next v7 14/22] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 15/22] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 16/22] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 17/22] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 18/22] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 19/22] selftests/bpf: Add end-to-end and negative .bpf_cleanup exception tests Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 1:42 ` Yonghong Song
2026-09-29 0:17 ` Yonghong Song [this message]
2026-09-29 0:52 ` [PATCH bpf-next v7 20/22] selftests/bpf: Add __set_global() and __ret_global() test tags bot+bpf-ci
2026-09-30 1:46 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 21/22] selftests/bpf: Cover more accepted .bpf_cleanup exception shapes Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 2:19 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 22/22] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 3:12 ` Yonghong Song
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929001746.3256138-1-yonghong.song@linux.dev \
--to=yonghong.song@linux.dev \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=kernel-team@fb.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.