All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH bpf-next 0/2] bpf: Reject offset refcount acquire arguments
@ 2026-06-19  7:59 Yiyang Chen
  2026-06-19  7:59 ` [PATCH bpf-next 1/2] " Yiyang Chen
                   ` (2 more replies)
  0 siblings, 3 replies; 11+ messages in thread
From: Yiyang Chen @ 2026-06-19  7:59 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Eduard Zingerman, Kumar Kartikeya Dwivedi
  Cc: Yiyang Chen, John Fastabend, Martin KaFai Lau, Song Liu,
	Yonghong Song, Jiri Olsa, Emil Tsalapatis, Shuah Khan,
	Viktor Malik, Leon Hwang, Dave Marchevsky, bpf, linux-kselftest,
	linux-kernel

bpf_refcount_acquire() is modeled as returning a refcounted allocation
base, but it currently accepts PTR_TO_BTF_ID | MEM_ALLOC arguments whose
offset already points at an embedded graph node returned from a list or
rbtree operation.

At runtime the kfunc starts from the supplied pointer and adds the type's
refcount offset.  With a graph-node pointer, that starts from base +
node_off, while the verifier treats the returned pointer as the allocation
base.  Reject non-zero-offset arguments to keep the runtime operation and
the verifier model aligned.

Programs that pop graph nodes can still acquire a reference after
normalizing the node pointer with container_of().

Patch 1 adds the verifier-side zero-offset check for
KF_ARG_PTR_TO_REFCOUNTED_KPTR.

Patch 2 adds regression coverage for the accepted container_of() case and
the rejected direct list and rbtree node cases.

Validation, rebased on current bpf-next master e771677c937d
("Merge tag 'for-linus-iommufd' of
git://git.kernel.org/pub/scm/linux/kernel/git/jgg/iommufd"):

  git ls-remote https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git \
    refs/heads/master: e771677c937d
  git diff --check e771677c937d..HEAD: OK
  make O=/root/ebpf-verifier-bug-detection/kernel-build/bpf-next-latest-20260618 \
    kernel/bpf/verifier.o: OK
  make -C tools/testing/selftests/bpf \
    O=/root/ebpf-verifier-bug-detection/kernel-build/bpf-next-latest-20260618 \
    OUTPUT=/tmp/c5-027-selftests \
    VMLINUX_BTF=/root/ebpf-verifier-bug-detection/kernel-build/bpf-next-latest-20260618/vmlinux \
    /tmp/c5-027-selftests/refcounted_kptr.bpf.o \
    /tmp/c5-027-selftests/refcounted_kptr_fail.bpf.o: OK
  make -C tools/testing/selftests/bpf ... BPF_STRICT_BUILD=0 test_progs: OK
  ./test_progs --list: listed refcounted_kptr and refcounted_kptr_fail

The BPF object build needed a local-only generated-vmlinux.h fixup for
missing experimental kfunc prototypes in this environment.  No source-tree
files were changed for that workaround.

The explicit runtime run was attempted with:

  ./test_progs -t refcounted_kptr

It failed before verifier checks in this local container because libbpf
could not load a trivial BPF program after failing to raise RLIMIT_MEMLOCK
(-EPERM).  The container's memlock limit is 64 KiB and cannot be raised
here ("Operation not permitted").

Yiyang Chen (2):
  bpf: Reject offset refcount acquire arguments
  selftests/bpf: Cover refcount acquire node offsets

 kernel/bpf/verifier.c                         |  5 ++
 .../selftests/bpf/progs/refcounted_kptr.c     | 33 ++++++++
 .../bpf/progs/refcounted_kptr_fail.c          | 84 +++++++++++++++++++
 3 files changed, 122 insertions(+)


base-commit: e771677c937da5808f7b6c1f0e4a97ec1a84f8a8
-- 
2.34.1


^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2026-06-20 17:48 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-19  7:59 [PATCH bpf-next 0/2] bpf: Reject offset refcount acquire arguments Yiyang Chen
2026-06-19  7:59 ` [PATCH bpf-next 1/2] " Yiyang Chen
2026-06-19 19:28   ` Eduard Zingerman
2026-06-19  7:59 ` [PATCH bpf-next 2/2] selftests/bpf: Cover refcount acquire node offsets Yiyang Chen
2026-06-19  8:30   ` sashiko-bot
2026-06-19  8:47   ` bot+bpf-ci
2026-06-19 19:30   ` Eduard Zingerman
2026-06-20 15:04 ` [PATCH bpf-next v2 0/2] bpf: Reject offset refcount acquire arguments Yiyang Chen
2026-06-20 15:04   ` [PATCH bpf-next v2 1/2] " Yiyang Chen
2026-06-20 17:48     ` Alexei Starovoitov
2026-06-20 15:04   ` [PATCH bpf-next v2 2/2] selftests/bpf: Cover refcount acquire node offsets Yiyang Chen

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.