All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Gabriele Monaco" <gmonaco@redhat.com>
Cc: linux-trace-kernel@vger.kernel.org, bpf@vger.kernel.org
Subject: Re: [PATCH v2 12/15] tools/rv: Add reactors support to BPF monitors
Date: Thu, 01 Oct 2026 15:57:18 +0000	[thread overview]
Message-ID: <20261001155718.AB41A1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261001152042.124445-13-gmonaco@redhat.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] bpf: panic reactor BPF program rejected due to PTR_TO_STACK argument
- [Medium] rv: NULL pointer dereference in list_reactor_action on missing BTF
--

commit fed00056d145e6ae07ec2d9b2b99084fea10c012
Author: Gabriele Monaco <gmonaco@redhat.com>

tools/rv: Add reactors support to BPF monitors

The commit adds reactors support to BPF monitors in the rv tool. It implements
rv_react to format and pass messages to a BPF function, which can be overridden
at load time by dynamically linking reactor object files like panic.o and
printk.o.

> diff --git a/tools/verification/rv/bpf_reactors/panic.c b/tools/verification/rv/bpf_reactors/panic.c
> new file mode 100644
> index 0000000000000..775f91a300f01
> --- /dev/null
> +++ b/tools/verification/rv/bpf_reactors/panic.c
> @@ -0,0 +1,15 @@
> +// SPDX-License-Identifier: GPL-2.0
> +
> +#include "vmlinux.h"
> +#include <bpf/bpf_helpers.h>
> +
> +void bpf_rv_react(char *msg)
> +{
> +	struct pt_regs regs = { 0 };
> +
> +	crash_kexec(&regs);

[Severity: Medium]
Will the BPF verifier reject this program? The &regs argument evaluates to a
PTR_TO_STACK register type, but crash_kexec expects a tracked PTR_TO_BTF_ID.

The verifier's check_kfunc_args strictly requires KF_ARG_PTR_TO_BTF_ID for
regular struct pointers unless explicitly tagged, so it may reject PTR_TO_STACK.

> +}

[ ... ]

> diff --git a/tools/verification/rv/src/bpf_monitor.c b/tools/verification/rv/src/bpf_monitor.c
> index d43ee75d3904f..35bd1f40a109c 100644
> --- a/tools/verification/rv/src/bpf_monitor.c
> +++ b/tools/verification/rv/src/bpf_monitor.c
> @@ -676,12 +679,31 @@ static struct ring_buffer *bpf_setup_ring_buffer(struct bpf_object *obj,
>  	return rb;
>  }
>  
> +static void list_reactor_action(const char *name, struct bpf_object *obj)
> +{
> +	const struct btf *btf = bpf_object__btf(obj);
> +
> +	if (btf__find_by_name_kind(btf, BPF_REACTOR, BTF_KIND_FUNC) >= 0)

[Severity: Medium]
Can this cause a NULL pointer dereference? If the object file lacks BTF
information (e.g., if it was stripped or compiled without -g), bpf_object__btf()
returns NULL.

btf__find_by_name_kind() then directly dereferences this NULL pointer in
libbpf's btf__type_cnt() without validation.

> +		fprintf(stderr, "%s ", name);
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261001152042.124445-1-gmonaco@redhat.com?part=12

  reply	other threads:[~2026-10-01 15:57 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 15:20 [PATCH v2 00/15] rv: Add support for BPF monitors Gabriele Monaco
2026-10-01 15:20 ` [PATCH v2 01/15] sched: Add task enqueue/dequeue trace points Gabriele Monaco
2026-10-01 15:49   ` Peter Zijlstra
2026-10-02  7:09     ` Gabriele Monaco
2026-10-02 10:29       ` Peter Zijlstra
2026-10-02 11:55         ` Gabriele Monaco
2026-10-02 19:18           ` Peter Zijlstra
2026-10-02 19:40             ` Gabriele Monaco
2026-10-04  7:57             ` Steven Rostedt
2026-10-04  7:45         ` Steven Rostedt
2026-10-02  0:42   ` bot+bpf-ci
2026-10-01 15:20 ` [PATCH v2 02/15] tools/rv: Skip empty pid error in selftest if command failed Gabriele Monaco
2026-10-02  0:42   ` bot+bpf-ci
2026-10-01 15:20 ` [PATCH v2 03/15] rv: Refactor da_trace() functions to get strings internally Gabriele Monaco
2026-10-01 15:20 ` [PATCH v2 04/15] rv: Cast result of model_get_*_name() Gabriele Monaco
2026-10-01 15:20 ` [PATCH v2 05/15] tools/rv: Move argument parsing from in_kernel to utils Gabriele Monaco
2026-10-02  0:25   ` bot+bpf-ci
2026-10-01 15:20 ` [PATCH v2 06/15] tools/build: Add a feature test for bpftool-btf Gabriele Monaco
2026-10-01 15:20 ` [PATCH v2 07/15] tools/rv: Implement BPF monitor discovery and listing Gabriele Monaco
2026-10-01 15:40   ` sashiko-bot
2026-10-02  0:42   ` bot+bpf-ci
2026-10-01 15:20 ` [PATCH v2 08/15] tools/rv: Implement BPF monitor loading and tracing Gabriele Monaco
2026-10-01 15:41   ` sashiko-bot
2026-10-02  0:43   ` bot+bpf-ci
2026-10-01 15:20 ` [PATCH v2 09/15] tools/rv: Copy stripped bpf_atomic.h from libarena Gabriele Monaco
2026-10-02  0:42   ` bot+bpf-ci
2026-10-07 12:59   ` Nam Cao
2026-10-08  9:00     ` Gabriele Monaco
2026-10-08 11:16       ` Nam Cao
2026-10-09 10:09         ` Gabriele Monaco
2026-10-01 15:20 ` [PATCH v2 10/15] tools/rv: Add BPF monitors Gabriele Monaco
2026-10-01 15:55   ` sashiko-bot
2026-10-02  0:43   ` bot+bpf-ci
2026-10-06 13:29   ` Alexei Starovoitov
2026-10-08  9:54     ` Gabriele Monaco
2026-10-01 15:20 ` [PATCH v2 11/15] tools/rv: Define CONFIG_X86_64 statically for " Gabriele Monaco
2026-10-01 15:49   ` sashiko-bot
2026-10-01 15:20 ` [PATCH v2 12/15] tools/rv: Add reactors support to " Gabriele Monaco
2026-10-01 15:57   ` sashiko-bot [this message]
2026-10-02  0:43   ` bot+bpf-ci
2026-10-01 15:20 ` [PATCH v2 13/15] verification/rvgen: Add support for " Gabriele Monaco
2026-10-02  0:25   ` bot+bpf-ci
2026-10-01 15:20 ` [PATCH v2 14/15] tools/rv: Add selftest for rv bpf monitors Gabriele Monaco
2026-10-01 16:03   ` sashiko-bot
2026-10-02  0:43   ` bot+bpf-ci
2026-10-01 15:20 ` [PATCH v2 15/15] verification/rvgen: Add selftest for rvgen -b Gabriele Monaco

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001155718.AB41A1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=gmonaco@redhat.com \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.