From: Yonghong Song <yonghong.song@linux.dev>
To: bot+bpf-ci@kernel.org, bpf@vger.kernel.org
Cc: ast@kernel.org, andrii@kernel.org, daniel@iogearbox.net,
eddyz87@gmail.com, kernel-team@fb.com, martin.lau@kernel.org,
mason@kernel.org, ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next v8 07/22] bpf: Follow an unwind to its landing pad in the verifier
Date: Fri, 2 Oct 2026 21:49:54 +0100 [thread overview]
Message-ID: <5b7579be-e885-4b5d-9336-b4aaa2cc09d4@linux.dev> (raw)
In-Reply-To: <344ff8ec93e6d083a2e73cf866699be96593f5c7d7e46b704f7dc2d69e76cf48@mail.kernel.org>
On 10/1/26 7:31 AM, bot+bpf-ci@kernel.org wrote:
>> bpf: Follow an unwind to its landing pad in the verifier
> TL;DR:
> - Global call that unwinds without a landing pad may hit a verifier bug
> warning in backtrack_insn() on fentry/cgroup_skb programs
> - bpf_unwind() skips no_stack_arg_load, so a stale R9 arg-6 load may pass
> verification
>
>> diff --git a/kernel/bpf/backtrack.c b/kernel/bpf/backtrack.c
>> index 0e38b9575328..f5504334df90 100644
>> --- a/kernel/bpf/backtrack.c
>> +++ b/kernel/bpf/backtrack.c
> [ ... ]
>
>> @@ -434,6 +458,24 @@ static int backtrack_insn(struct bpf_verifier_env *env, int idx, int subseq_idx,
>> return -EFAULT;
>> }
>>
>> + if (bpf_exc_pad_of_call(env, idx) == subseq_idx) {
>> + /*
>> + * We came from the landing pad of a call to a
>> + * global subprog, branched to from the state
>> + * the call returns in: as on its return, no
>> + * frame was entered here. The call clobbered
>> + * r0-r5; r6-r9 and the stack are the caller's
>> + * own and keep going back from here.
>> + */
>> + bt_clear_reg(bt, BPF_REG_0);
>> + if (bt_reg_mask(bt) & BPF_REGMASK_ARGS) {
>> + verifier_bug(env, "landing pad unexpected regs %x",
>> + bt_reg_mask(bt));
>> + return -EFAULT;
>> + }
>> + return 0;
>> + }
>> +
>> /* callx calls static subprogs only */
>> if (subprog >= 0 && bpf_subprog_is_global(env, subprog)) {
>> /* check that jump history doesn't have any
> Can the existing idx + 1 != subseq_idx check in this global branch now fire
> for a global call that unwinds with no landing pad?
>
> verifier_bug_if(idx + 1 != subseq_idx, env,
> "extra insn from subprog");
>
> In that case unwind_out_of_global_call() takes the pad < 0 path into
> unwind_frames(), and when unwind_frames() reaches the main frame it pushes a
> history entry with no flags:
>
> env->prev_insn_idx = env->insn_idx;
> env->insn_idx = state->insn_idx;
> err = bpf_push_jmp_history(env, state, 0, 0, 0, NULL, 0);
> ...
> return process_bpf_exit_full(env, do_print_state, false);
>
> The entry's prev_idx is the global call insn, so INSN_F_UNWIND is not set.
> For program types where return_retval_range() returns true (fentry/fexit,
> cgroup_skb, struct_ops), process_bpf_exit_full() -> check_return_code() calls
> mark_chain_precision(env, BPF_REG_0).
>
> The backtrack then reaches backtrack_insn() with idx at the global call and
> subseq_idx at either the same insn (call in main) or the call site in main
> (static frames popped first). The INSN_F_UNWIND branch does not match, the
> bpf_exc_pad_of_call() == subseq_idx branch does not match because no pad
> covers the call, and the walk lands in the global branch above, where
> idx + 1 != subseq_idx is true.
>
> The result is a WARN_ONCE() (a panic with panic_on_warn) and a "verifier bug"
> message in the log, although the program is still accepted. An example is an
> fentry or cgroup_skb program calling a global subprog that calls
> bpf_unwind() with no record covering the call, or main -> static A -> global
> G with no records.
>
> The selftests in the series all use SEC("syscall"), where
> return_retval_range() returns false and r0 precision is never requested at
> exit, so they would not reach this. Nothing later in the series touches
> backtrack.c.
>
> Should the main-exit history entry get its own flag, or should this global
> branch handle that entry before applying the idx + 1 check?
Yes, this global branch should handle that entry before applying the idx + 1
check (global function) and we can add INSN_F_UNWIND to this jump history
to keep later continuing doing static function.
>
> [ ... ]
>
>> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
>> index 80034429fdd0..c7a350be538e 100644
>> --- a/kernel/bpf/verifier.c
>> +++ b/kernel/bpf/verifier.c
> [ ... ]
>
>> @@ -19380,13 +19520,32 @@ static int do_check_insn(struct bpf_verifier_env *env, bool *do_print_state)
>> return -EINVAL;
>> }
>> }
>> + if (bpf_is_unwind_kfunc(insn) || bpf_is_unwind_resume_kfunc(insn)) {
>> + err = check_kfunc_allowed_only(env, insn, env->insn_idx);
>> + if (err)
>> + return err;
>> + if (bpf_is_unwind_kfunc(insn))
>> + return process_bpf_unwind(env, &env->insn_idx,
>> + do_print_state);
>> + /*
>> + * The fixups lower this to 'r0 = 0; exit', and
>> + * the unwind goes on below this frame.
>> + */
>> + return unwind_frames(env, do_print_state);
>> + }
>> mark_reg_scratched(env, BPF_REG_0);
>> if (bpf_in_stack_arg_cnt(&env->subprog_info[cur_func(env)->subprogno]))
>> cur_func(env)->no_stack_arg_load = true;
> Does this early return skip the no_stack_arg_load assignment that every
> other call insn gets?
>
> For bpf_unwind() with a pad in the same frame, process_bpf_unwind() goes on
> at the pad in the frame that made the call, with no_stack_arg_load still
> false:
>
> clear_caller_saved_regs(env, frame->regs);
> mark_reg_unknown(env, frame->regs, BPF_REG_0);
> *insn_idx = pad;
> return INSN_IDX_UPDATED;
>
> On x86, do_jit() turns a load from BPF_REG_PARAMS at offset 8 (incoming
> arg 6) into a read of R9, which is caller-saved and clobbered by any call.
> check_stack_arg_read() relies on no_stack_arg_load to reject such a load
> after a call.
>
> So in a subprog with more than 5 args, would this sequence pass
> verification?
>
> call bpf_unwind // record covers it, pad P in this frame
> P:
> r1 = *(u64 *)(r11 + 8) // incoming arg 6
> r2 = *(u64 *)(r1 + 0)
>
> check_stack_arg_read() gives r1 the type of caller->stack_arg_regs[0], which
> can be any spilled type, including a pointer such as PTR_TO_MAP_VALUE, but
> at run time r1 holds whatever bpf_unwind() left in R9.
>
> Would it work to move the mark_reg_scratched() and no_stack_arg_load lines
> above the unwind branch, or to set cur_func(env)->no_stack_arg_load in
> process_bpf_unwind() before going on at the pad?
>
> The unwind_out_of_global_call() pad path looks unaffected, since the
> PSEUDO_CALL path sets the flag before check_func_call(). do_check_insn()
> has the same ordering at the end of the series, where both kfuncs become
> callable.
Yes, you are right. The below:
mark_reg_scratched(env, BPF_REG_0);
if (bpf_in_stack_arg_cnt(&env->subprog_info[cur_func(env)->subprogno]))
cur_func(env)->no_stack_arg_load = true;
should be moved earlier so later some prog checking can inherit some
choices.
>
> ---
> AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
> See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
>
> CI run summary: https://github.com/kernel-patches/bpf/actions/runs/36872142096
next prev parent reply other threads:[~2026-10-02 20:49 UTC|newest]
Thread overview: 50+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 13:30 [PATCH bpf-next v8 00/22] bpf: Run exception cleanup landing pads when bpf_unwind() unwinds Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 01/22] bpf: Pack bpf_insn_aux_data flags into bit fields Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 02/22] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 03/22] bpf: Add the bpf_unwind() and bpf_unwind_resume() kfuncs Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 04/22] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-10-01 13:48 ` sashiko-bot
2026-10-02 18:17 ` Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 05/22] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-10-01 14:31 ` bot+bpf-ci
2026-10-02 19:06 ` Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 06/22] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 07/22] bpf: Follow an unwind to its landing pad in the verifier Yonghong Song
2026-10-01 13:50 ` sashiko-bot
2026-10-02 19:31 ` Yonghong Song
2026-10-01 14:31 ` bot+bpf-ci
2026-10-02 20:49 ` Yonghong Song [this message]
2026-10-03 12:23 ` Alexei Starovoitov
2026-10-04 17:56 ` Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 08/22] bpf: Require an unwind to leave a frame holding what it entered with Yonghong Song
2026-10-01 14:31 ` bot+bpf-ci
2026-10-02 21:10 ` Yonghong Song
2026-10-03 12:25 ` Alexei Starovoitov
2026-10-04 17:59 ` Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 09/22] bpf: Refuse a landing pad that does not resume Yonghong Song
2026-10-03 12:25 ` Alexei Starovoitov
2026-10-04 18:26 ` Yonghong Song
2026-10-01 13:30 ` [PATCH bpf-next v8 10/22] bpf: Do not use a private stack for a program that can unwind Yonghong Song
2026-10-01 13:53 ` sashiko-bot
2026-10-02 21:38 ` Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 11/22] bpf: Dispatch cleanup pads by rewriting return addresses Yonghong Song
2026-10-01 14:31 ` bot+bpf-ci
2026-10-02 21:48 ` Yonghong Song
2026-10-03 12:26 ` Alexei Starovoitov
2026-10-04 18:28 ` Yonghong Song
2026-10-04 18:29 ` Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 12/22] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-10-01 13:49 ` sashiko-bot
2026-10-02 21:54 ` Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 13/22] bpf, arm64: " Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 14/22] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 15/22] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-10-01 13:46 ` sashiko-bot
2026-10-02 22:09 ` Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 16/22] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 17/22] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 18/22] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 19/22] selftests/bpf: Add end-to-end and negative .bpf_cleanup exception tests Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 20/22] selftests/bpf: Add __set_global() and __ret_global() test tags Yonghong Song
2026-10-01 13:31 ` [PATCH bpf-next v8 21/22] selftests/bpf: Cover more accepted .bpf_cleanup exception shapes Yonghong Song
2026-10-01 13:32 ` [PATCH bpf-next v8 22/22] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5b7579be-e885-4b5d-9336-b4aaa2cc09d4@linux.dev \
--to=yonghong.song@linux.dev \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bot+bpf-ci@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=ihor.solodrai@linux.dev \
--cc=kernel-team@fb.com \
--cc=martin.lau@kernel.org \
--cc=mason@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.