All of lore.kernel.org
 help / color / mirror / Atom feed
From: Yonghong Song <yonghong.song@linux.dev>
To: bot+bpf-ci@kernel.org, bpf@vger.kernel.org
Cc: ast@kernel.org, andrii@kernel.org, daniel@iogearbox.net,
	eddyz87@gmail.com, kernel-team@fb.com, martin.lau@kernel.org,
	mason@kernel.org, ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next v7 08/22] bpf: Require an unwind to leave a frame holding what it entered with
Date: Tue, 29 Sep 2026 18:10:45 -0700	[thread overview]
Message-ID: <837734d4-de88-437f-bc16-3ffadb713ec1@linux.dev> (raw)
In-Reply-To: <7d45bfa94899a2626f053f2c0fd517a074a422d796ed64389a9033c9512efd7b@mail.kernel.org>



On 9/28/26 5:52 PM, bot+bpf-ci@kernel.org wrote:
>> A landing pad's entry state is the state at the call it belongs to, taken
>> before the callee ran -- push_cleanup_pad_branch() snapshots it there. That
>> is right for the frame's own registers and stack, which the callee's
>> epilogue puts back, and wrong for what the program shares: nothing restores
>> the locks in bpf_verifier_state.
> Is the claim about the callee's epilogue restoring the caller's stack
> accurate?
>
> Looking at the BPF calling convention, the callee's epilogue only restores
> r6-r9 and the frame pointer. It does not restore the caller's BPF stack
> slots. A callee that receives a PTR_TO_STACK into the caller's frame can
> write that stack freely, and those writes are not restored on return.
>
> For example, if the caller spills a map value pointer to fp-8 and calls
> foo(fp-8) under a landing pad, foo can store an arbitrary scalar to
> *(u64 *)(r1 + 0) and then call bpf_unwind(). The caller's pad would be
> verified from the pre-call snapshot where fp-8 still holds the spilled
> map value pointer, but at run time the pad would load the
> attacker-controlled scalar.
>
> The same issue applies to any stack slot type change that the callee makes
> before unwinding, such as spilled pointers overwritten by stack writes, or
> dynptr and iterator slots clobbered by the callee.
>
> Should the commit message clarify what the epilogue actually restores?

Yes, this is a problem. I had some comments in patch 7. Will fix.

>
>
> ---
> AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
> See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
>
> CI run summary: https://github.com/kernel-patches/bpf/actions/runs/36502848904


  reply	other threads:[~2026-09-30  1:10 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  0:16 [PATCH bpf-next v7 00/22] bpf: Run exception cleanup landing pads when bpf_unwind() unwinds Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 01/22] bpf: Pack bpf_insn_aux_data flags into bit fields Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 02/22] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 03/22] bpf: Add the bpf_unwind() and bpf_unwind_resume() kfuncs Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 04/22] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-29  0:33   ` sashiko-bot
2026-09-29 21:58     ` Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 05/22] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-29  0:31   ` sashiko-bot
2026-09-29 22:04     ` Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 06/22] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 07/22] bpf: Resume a covered call at its landing pad Yonghong Song
2026-09-29  0:31   ` sashiko-bot
2026-09-30  0:28     ` Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 08/22] bpf: Require an unwind to leave a frame holding what it entered with Yonghong Song
2026-09-29  0:36   ` sashiko-bot
2026-09-30  1:09     ` Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  1:10     ` Yonghong Song [this message]
2026-09-29  0:16 ` [PATCH bpf-next v7 09/22] bpf: Refuse a landing pad that does not resume Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 10/22] bpf: Refuse a private stack for a program that can unwind Yonghong Song
2026-09-29  0:16 ` [PATCH bpf-next v7 11/22] bpf: Dispatch cleanup pads by rewriting return addresses Yonghong Song
2026-09-29  1:14   ` bot+bpf-ci
2026-09-30  1:18     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 12/22] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-29  0:30   ` sashiko-bot
2026-09-30  1:34     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 13/22] bpf, arm64: " Yonghong Song
2026-09-29  1:14   ` bot+bpf-ci
2026-09-29  0:17 ` [PATCH bpf-next v7 14/22] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 15/22] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 16/22] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 17/22] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 18/22] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 19/22] selftests/bpf: Add end-to-end and negative .bpf_cleanup exception tests Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  1:42     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 20/22] selftests/bpf: Add __set_global() and __ret_global() test tags Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  1:46     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 21/22] selftests/bpf: Cover more accepted .bpf_cleanup exception shapes Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  2:19     ` Yonghong Song
2026-09-29  0:17 ` [PATCH bpf-next v7 22/22] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
2026-09-29  0:52   ` bot+bpf-ci
2026-09-30  3:12     ` Yonghong Song

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=837734d4-de88-437f-bc16-3ffadb713ec1@linux.dev \
    --to=yonghong.song@linux.dev \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bot+bpf-ci@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=ihor.solodrai@linux.dev \
    --cc=kernel-team@fb.com \
    --cc=martin.lau@kernel.org \
    --cc=mason@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.