From: sashiko-bot@kernel.org
To: "Yonghong Song" <yonghong.song@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v7 08/22] bpf: Require an unwind to leave a frame holding what it entered with
Date: Tue, 29 Sep 2026 00:36:38 +0000 [thread overview]
Message-ID: <20260929003638.8A1181F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929001643.3249386-1-yonghong.song@linux.dev>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Critical] bpf: type confusion and memory corruption due to stale cleanup pad state
- [High] bpf: lock corruption and double-unlock via missing identity check on unwind
--
commit 585aa50d9e8811792b9a816a4d1ad6cd51d63ea7
Author: Yonghong Song <yonghong.song@linux.dev>
Subject: bpf: Require an unwind to leave a frame holding what it entered with
This commit updates the BPF verifier to record what locks and references
a program holds when a frame is entered. It enforces that an unwind must
leave the frame holding what it entered with, ensuring that landing pads
verified against pre-call snapshots remain valid.
> diff --git a/include/linux/bpf_verifier.h b/include/linux/bpf_verifier.h
> index 0143688896b0e..75e572a8a1bab 100644
> --- a/include/linux/bpf_verifier.h
> +++ b/include/linux/bpf_verifier.h
> @@ -339,6 +339,18 @@ struct bpf_func_state {
> bool in_async_callback_fn;
> bool in_exception_callback_fn;
> bool no_stack_arg_load;
> + /*
> + * What the program held when this frame was entered. An unwind leaves
> + * the frame without running anything below it, so the frame has to put
> + * these back to what it found before it goes -- otherwise a caller's
> + * landing pad, whose state was taken at the call, is wrong about them.
> + */
> + u32 entry_active_locks;
> + u32 entry_preempt_locks;
> + u32 entry_rcu_locks;
> + u32 entry_irq_id;
> + u32 entry_id_gen;
> + u32 entry_acquired_refs;
[Severity: High]
Does this structure need fields to record the identity of the lock held upon
frame entry? Without this, it might be difficult to accurately enforce the
correct lock state on unwind.
Additionally, is it necessary to update func_states_equal() to compare these
new entry_* fields? Without comparing them, could the verifier unsafely prune
states with different entry locking conditions?
[ ... ]
> diff --git a/kernel/bpf/exception.c b/kernel/bpf/exception.c
> index c1779d2d02f05..c0b0b8478af51 100644
> --- a/kernel/bpf/exception.c
> +++ b/kernel/bpf/exception.c
> @@ -12,6 +12,72 @@
> BTF_ID_LIST_SINGLE(bpf_unwind_id, func, bpf_unwind)
> BTF_ID_LIST_SINGLE(bpf_unwind_resume_id, func, bpf_unwind_resume)
>
> +void bpf_exc_record_frame_entry(const struct bpf_verifier_state *state,
> + struct bpf_func_state *frame, u32 id_gen)
> +{
[ ... ]
> +int bpf_exc_check_frame_balance(struct bpf_verifier_env *env, const char *prefix)
> +{
> + const struct bpf_verifier_state *state = env->cur_state;
> + const struct bpf_func_state *frame = cur_func(env);
> + u32 i, held;
> + const char *what;
> +
> + if (state->active_rcu_locks != frame->entry_rcu_locks)
> + what = "bpf_rcu_read_lock";
> + else if (state->active_preempt_locks != frame->entry_preempt_locks)
> + what = "bpf_preempt_disable";
> + else if (state->active_irq_id != frame->entry_irq_id)
> + what = "bpf_local_irq_save";
> + else if (state->active_locks != frame->entry_active_locks)
> + what = "bpf_spin_lock";
[Severity: High]
Does this code adequately verify lock identity? While it checks the count of
active locks, it appears to miss checking the identity of the lock
(active_lock_id and active_lock_ptr).
If a BPF program acquires lock A, passes it to a subprogram which unlocks A,
locks B, and then throws an exception (bpf_unwind()), could the unwinder
accept the frame balance since the active_locks count is still 1?
The exception would jump back to the caller's cleanup pad, which assumes
lock A is still held. The cleanup pad unlocking A could potentially cause a
double-unlock of lock A and leak lock B forever.
> + else
> + what = NULL;
[ ... ]
> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index ee074d4a936b5..4bdee3f02fe9d 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
[ ... ]
> @@ -19512,6 +19554,10 @@ static int do_check_insn(struct bpf_verifier_env *env, bool *do_print_state)
> mark_reg_scratched(env, BPF_REG_0);
> /* An unwind out of this call resumes at the pad. */
> err = push_cleanup_pad_branch(env, env->insn_idx);
[Severity: Critical]
Does taking a pre-call snapshot of the verifier state for the cleanup pad
incorrectly ignore valid memory modifications made by the callee before
unwinding?
For example, if a caller spills a valid pointer to its stack and passes a
pointer to this stack slot to a subprogram:
- The verifier schedules the caller's cleanup pad branch by pushing a snapshot
of the verifier state (including the stack) taken BEFORE the callee runs.
- The subprogram overwrites the caller's stack slot with an attacker-controlled
scalar and calls bpf_unwind().
- At runtime, the exception jumps to the cleanup pad, which loads the scalar.
Because the cleanup pad uses the pre-call snapshot, does the verifier
incorrectly assume the loaded value is still a valid pointer, potentially
leading to type confusion and memory corruption?
> + if (err)
> + return err;
> + /* Or, with no pad, leaves the frame for good. */
> + err = check_unwind_through_call(env, env->insn_idx);
> if (err)
> return err;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929001601.3242665-1-yonghong.song@linux.dev?part=8
next prev parent reply other threads:[~2026-09-29 0:36 UTC|newest]
Thread overview: 46+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 0:16 [PATCH bpf-next v7 00/22] bpf: Run exception cleanup landing pads when bpf_unwind() unwinds Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 01/22] bpf: Pack bpf_insn_aux_data flags into bit fields Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 02/22] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 03/22] bpf: Add the bpf_unwind() and bpf_unwind_resume() kfuncs Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 04/22] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-29 0:33 ` sashiko-bot
2026-09-29 21:58 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 05/22] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-29 0:31 ` sashiko-bot
2026-09-29 22:04 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 06/22] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 07/22] bpf: Resume a covered call at its landing pad Yonghong Song
2026-09-29 0:31 ` sashiko-bot
2026-09-30 0:28 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 08/22] bpf: Require an unwind to leave a frame holding what it entered with Yonghong Song
2026-09-29 0:36 ` sashiko-bot [this message]
2026-09-30 1:09 ` Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 1:10 ` Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 09/22] bpf: Refuse a landing pad that does not resume Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 10/22] bpf: Refuse a private stack for a program that can unwind Yonghong Song
2026-09-29 0:16 ` [PATCH bpf-next v7 11/22] bpf: Dispatch cleanup pads by rewriting return addresses Yonghong Song
2026-09-29 1:14 ` bot+bpf-ci
2026-09-30 1:18 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 12/22] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-29 0:30 ` sashiko-bot
2026-09-30 1:34 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 13/22] bpf, arm64: " Yonghong Song
2026-09-29 1:14 ` bot+bpf-ci
2026-09-29 0:17 ` [PATCH bpf-next v7 14/22] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 15/22] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 16/22] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 17/22] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 18/22] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 19/22] selftests/bpf: Add end-to-end and negative .bpf_cleanup exception tests Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 1:42 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 20/22] selftests/bpf: Add __set_global() and __ret_global() test tags Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 1:46 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 21/22] selftests/bpf: Cover more accepted .bpf_cleanup exception shapes Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 2:19 ` Yonghong Song
2026-09-29 0:17 ` [PATCH bpf-next v7 22/22] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
2026-09-29 0:52 ` bot+bpf-ci
2026-09-30 3:12 ` Yonghong Song
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929003638.8A1181F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.