From: "Kumar Kartikeya Dwivedi" <memxor@gmail.com>
To: "Ning Ding" <dingning04@gmail.com>, <bpf@vger.kernel.org>
Cc: <greg@kroah.com>
Subject: Re: [PATCH bpf-next v4 0/4] bpf: Fix refcount_acquire handling for borrowed kptrs
Date: Fri, 04 Sep 2026 08:40:08 +0200 [thread overview]
Message-ID: <DL6BRAOHPT5T.8N108I2TRDJX@gmail.com> (raw)
In-Reply-To: <20260813211533.290256-1-dingning04@gmail.com>
On Thu Aug 13, 2026 at 11:15 PM CEST, Ning Ding wrote:
> Fix two verifier bugs involving bpf_refcount_acquire() and map kptrs.
>
> First, the verifier can mistake an RCU-loaded map kptr for an owned
> reference and assume bpf_refcount_acquire() cannot return NULL. The kfunc
> can return NULL after the last reference is dropped, so passing an
> unchecked result to bpf_obj_drop() can crash the kernel.
>
> Second, type_is_ptr_alloc_obj() accepts PTR_UNTRUSTED pointers. This lets a
> pointer that is no longer protected by RCU reach bpf_refcount_acquire(). If
> the object was freed and its address reused, the verifier may acquire a
> reference through stale memory.
>
> Patches 1 and 2 fix and test the return-value nullability. Patches 3 and 4
> reject untrusted allocated-object pointers while keeping safe
> BPF_PROBE_MEM reads accepted.
>
> The series is based on bpf-next commit 806c1a185215
> ("Merge branch 'bpf-introduce-global-percpu-data'").
>
> Testing used a fresh virtme-ng KVM boot with KASAN enabled:
>
> full test_progs: 757/6685 passed, 7858 skipped, 0/0 failed
> KASAN/Oops/panic markers: none
>
Hi Ning, thanks for the patches, and sorry for the delay on this set. I've been
buried with several other fixes. Nicholas also reported similar issues, and
there were unresolved AI issues here, so I've taken over the series and made
some adjustments and sent a new version here, which I think should address all
concerns properly. If you have some time, please take a look and let me know if
you see any issues [0].
I have kept your authorship to credit you for the original work on this. Thanks.
[0]: https://lore.kernel.org/bpf/20260904063650.3877826-1-memxor@gmail.com
> ---
> v4:
> - Rebase and retarget the series onto bpf-next.
> - Change only the affected verifier test program sections from ?tc to
> sleepable ?syscall, as suggested by Kumar Kartikeya Dwivedi; leave the
> test logic unchanged.
> - Drop Cc: stable@vger.kernel.org.
> - Rerun the full unfiltered test_progs suite.
>
> v3:
> - Make type_is_ptr_alloc_obj() reject PTR_UNTRUSTED, as suggested by
> Kumar Kartikeya Dwivedi.
> - Add a separate helper for the BPF_PROBE_MEM read path.
> - Add read, refcount-acquire, and direct-write verifier tests.
> - Add Cc: stable@vger.kernel.org to both fixes, as requested by Greg
> Kroah-Hartman.
> - Split each fix from its selftests.
>
> v3: https://lore.kernel.org/r/20260803112218.3361213-1-dingning04@gmail.com
> v2: https://lore.kernel.org/r/20260726235030.1152542-1-dingning04@gmail.com
> v1: https://lore.kernel.org/r/20260726015330.705259-1-dingning04@gmail.com
>
> Ning Ding (4):
> bpf: Keep refcount_acquire nullable for borrowed RCU kptrs
> selftests/bpf: Test refcount_acquire return nullability
> bpf: Reject untrusted allocated-object pointers
> selftests/bpf: Test untrusted allocated-object pointers
>
> include/linux/bpf_verifier.h | 11 +-
> kernel/bpf/verifier.c | 10 +-
> .../selftests/bpf/progs/refcounted_kptr.c | 161 ++++++++++++++++++
> .../bpf/progs/refcounted_kptr_fail.c | 74 ++++++++
> 4 files changed, 253 insertions(+), 3 deletions(-)
>
>
> base-commit: 806c1a185215382fab5a7fafc74e30070b2fb043
prev parent reply other threads:[~2026-09-04 6:40 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 21:15 [PATCH bpf-next v4 0/4] bpf: Fix refcount_acquire handling for borrowed kptrs Ning Ding
2026-08-13 21:15 ` [PATCH bpf-next v4 1/4] bpf: Keep refcount_acquire nullable for borrowed RCU kptrs Ning Ding
2026-08-13 21:15 ` [PATCH bpf-next v4 2/4] selftests/bpf: Test refcount_acquire return nullability Ning Ding
2026-08-13 22:26 ` bot+bpf-ci
2026-08-13 21:15 ` [PATCH bpf-next v4 3/4] bpf: Reject untrusted allocated-object pointers Ning Ding
2026-08-13 22:26 ` bot+bpf-ci
2026-08-14 1:01 ` Ning Ding
2026-08-14 1:50 ` sashiko-bot
2026-08-13 21:15 ` [PATCH bpf-next v4 4/4] selftests/bpf: Test " Ning Ding
2026-08-13 22:10 ` bot+bpf-ci
2026-09-04 6:40 ` Kumar Kartikeya Dwivedi [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DL6BRAOHPT5T.8N108I2TRDJX@gmail.com \
--to=memxor@gmail.com \
--cc=bpf@vger.kernel.org \
--cc=dingning04@gmail.com \
--cc=greg@kroah.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.